SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-
ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag
jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sor
Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing
jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a c
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss
Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogX
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO
Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOff
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functi
In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix recursive locking in __configfs_o
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that
ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
FC-SWILS protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
In the Linux kernel, the following vulnerability has been resolved: l2tp: Drop large packets with UDP encap syzbot rep
jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detectio
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads. This is
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Es
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leadin
In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: fix recursive pci_lock_rescan_remove l
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Frequently Asked Questions
What is CWE-674?
CWE-674 (CWE-674) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-674?
There are 578 CVE records associated with CWE-674 in our database. Of these, 6 are critical severity, 227 are high severity, and 242 are medium severity.
How can I protect against CWE-674 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-674 using AI-powered security agents.
Detect CWE-674 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-674 vulnerabilities across your infrastructure.
Get Started