CWE-606: Unchecked Input for Loop Condition
The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
33 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-11972 — tarfile opened in streaming mode mishandles EOF
- CVE-2026-27689 — Denial of service (DOS) in SAP Supply Chain Management
- CVE-2026-23689 — Denial of service (DOS) in SAP Supply Chain Management
- CVE-2024-13931 — Authenticated Relative Path Traversal
- CVE-2026-13761 — Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
- CVE-2026-20301 — Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
- CVE-2025-43801 — Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppo
- CVE-2019-25624 — Liquid Studio 2.17 Denial of Service via Malformed Input
- CVE-2026-85730 — smol-toml: Denial of Service via malformed TOML documents
- CVE-2025-42930 — Denial of Service (DoS) vulnerability in SAP Business Planning and Consolidation
- CVE-2026-1519 — Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
- CVE-2026-33800 — Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash
- CVE-2024-13930 — Authenticated Unchecked Loop Condition
- CVE-2026-55731 — Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent
- CVE-2026-68077 — Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
- CVE-2026-66276 — Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
- CVE-2026-67554 — Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
- CVE-2025-32399 — An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices t
- CVE-2026-15172 — Unchecked Input for Loop Condition in Wireshark
- CVE-2026-71439 — Mermaid radar diagrams are vulnerable to DoS
Recently published
- CVE-2026-85730 — smol-toml: Denial of Service via malformed TOML documents
- CVE-2026-13761 — Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
- CVE-2026-16599 — Denial of Service in GNU wget
- CVE-2026-71439 — Mermaid radar diagrams are vulnerable to DoS
- CVE-2026-20301 — Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
- CVE-2026-67554 — Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
- CVE-2026-68077 — Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
- CVE-2026-66276 — Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
- CVE-2026-55731 — Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent
- CVE-2026-33800 — Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash
- CVE-2026-15172 — Unchecked Input for Loop Condition in Wireshark
- CVE-2026-11972 — tarfile opened in streaming mode mishandles EOF
- CVE-2026-41986 — Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi
- CVE-2026-5950 — Unbounded resend loop in BIND 9 resolver
- CVE-2026-0243 — Prisma SD-WAN: Denial of Service (DoS) Vulnerability Through IPv6 Crafted Packet
- CVE-2026-1519 — Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
- CVE-2019-25624 — Liquid Studio 2.17 Denial of Service via Malformed Input
- CVE-2026-27689 — Denial of service (DOS) in SAP Supply Chain Management
- CVE-2026-23689 — Denial of service (DOS) in SAP Supply Chain Management
- CVE-2025-43801 — Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppo