Threats Tagged 'cwe-674'
View all threats tagged with 'cwe-674'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-674'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54269: CWE-674: Uncontrolled Recursion in protobufjs protobuf.jsCVE-2026-54269 0 protobuf.js versions prior to 8.6.0 and 7.6.3 contain a vulnerability where certain schema-derived names can collide with internal runtime helper properties. This can cause uncontrolled recursion or deterministic exceptions during decoding, verification, object conversion, JSON serialization, or RPC helper invocation. The issue arises from accepting field or service method names like hasOwnProperty, $type, or rpcCall that interfere with protobufjs internals. This vulnerability has a medium severity score of 5.3 and is fixed in versions 8.6.0 and 7.6.3. Join the discussion | CVE Database V5 | 06/22/2026, 16:23:24 UTC Added: 06/22/2026, 17:39:39 UTC |
CVE-2026-48712: CWE-674: Uncontrolled Recursion in protobufjs protobuf.jsCVE-2026-48712 0 protobuf.js versions prior to 7.6.1 and 8.4.1 contain an uncontrolled recursion vulnerability in the toObject() conversion and custom google.protobuf.Any JSON conversion. This can cause a JavaScript call stack exhaustion when processing crafted protobuf binaries with deeply nested Any values. The issue is fixed in versions 7.6.1 and 8.4.1. Join the discussion | CVE Database V5 | 06/22/2026, 16:21:21 UTC Added: 06/22/2026, 17:39:38 UTC |
CVE-2025-7010: CWE-674 Uncontrolled Recursion in Gen Digital Avast AntivirusCVE-2025-7010 0 Stack overflow vulnerability due to uncontrolled recursion in Avast Antivirus when scanning a malformed PDF file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021208. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream. Join the discussion | CVE Database V5 | 06/12/2026, 22:11:22 UTC Added: 06/12/2026, 22:24:26 UTC |
CVE-2025-7005: CWE-674 Uncontrolled Recursion in Gen Digital Avast AntivirusCVE-2025-7005 0 Uncontrolled recursion vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25031700. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream. Join the discussion | CVE Database V5 | 06/12/2026, 22:07:35 UTC Added: 06/12/2026, 22:24:26 UTC |
CVE-2026-9740: CWE-674 Uncontrolled Recursion in MongoDB MongoDB ServerCVE-2026-9740 0 A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures permits uncontrolled mutual recursion between validation functions, where each re-entry resets internal depth tracking. Join the discussion | CVE Database V5 | 06/09/2026, 22:43:44 UTC Added: 06/09/2026, 22:55:45 UTC |
CVE-2026-49847: CWE-674: Uncontrolled Recursion in signalwire freeswitchCVE-2026-49847 0 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH process via stack overflow, terminating all calls and sessions on the host. The recursion drives the worker thread's stack pointer into the stack guard page, raising SIGSEGV from the kernel before any usable write primitive develops. This issue has been patched in version 1.11.1. Join the discussion | CVE Database V5 | 06/09/2026, 16:05:08 UTC Added: 06/09/2026, 16:26:03 UTC |
CVE-2026-49941: CWE-1287 Improper Validation of Specified Type of Input in RRWO Net::CIDR::SetCVE-2026-49941 0 Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask. If the argument was not a well-formed IP address, then this would lead to indefinite recursion. An attacker could use this to cause a denial of service. Join the discussion | CVE Database V5 | 06/04/2026, 16:07:20 UTC Added: 06/04/2026, 16:48:45 UTC |
CVE-2026-47706: CWE-400: Uncontrolled Resource Consumption in strawberry-graphql strawberryCVE-2026-47706 0 Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue. Join the discussion | CVE Database V5 | 06/04/2026, 14:06:48 UTC Added: 06/04/2026, 14:33:50 UTC |
CVE-2026-47320: CWE-824 Access of uninitialized pointer in Samsung Open Source rlottieCVE-2026-47320 0 Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3. Join the discussion | CVE Database V5 | 06/04/2026, 09:38:27 UTC Added: 06/04/2026, 10:04:06 UTC |
CVE-2026-47306: CWE-674 Uncontrolled Recursion in Samsung Open Source rlottieCVE-2026-47306 0 Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945. Join the discussion | CVE Database V5 | 06/04/2026, 09:43:14 UTC Added: 06/04/2026, 10:04:06 UTC |
Showing 1 to 10 of 17 results