In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure tha
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, conta
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_i
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP conn
MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON input
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled
XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21,
When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list acc
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R
Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attacke
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticate
Helm is a package manager for Charts for Kubernetes. A JSON Schema file within a chart can be crafted with a deeply nest
In ims service, there is a possible system crash due to incorrect error handling. This could lead to remote denial of se
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion
Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a de
Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to caus
A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputSt
Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade
Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of
An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consum
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Check for any of tcp_bpf_prots when c
In the Linux kernel, the following vulnerability has been resolved: perf: Improve missing SIGTRAP checking To catch mi
In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: Add 'plane' value check Function di
In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Optimize clearing the pending PMI and
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: Check dsbr size from EFI variab
In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix crash in timerlat_dump_stack()
In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors ch
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local
In the Linux kernel, the following vulnerability has been resolved: powercap: arm_scmi: Remove recursion while parsing
In the Linux kernel, the following vulnerability has been resolved: nbd: fix incomplete validation of ioctl arg We tes
In the Linux kernel, the following vulnerability has been resolved: rcu: Avoid stack overflow due to __rcu_irq_enter_ch
Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary numb
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with comm
The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from f
Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticate
cpdf through 2.8 allows stack consumption via a crafted PDF document.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12
VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMa
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the f
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within t
Frequently Asked Questions
What is CWE-674?
CWE-674 (CWE-674) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-674?
There are 578 CVE records associated with CWE-674 in our database. Of these, 6 are critical severity, 227 are high severity, and 242 are medium severity.
How can I protect against CWE-674 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-674 using AI-powered security agents.
Detect CWE-674 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-674 vulnerabilities across your infrastructure.
Get Started