CWE-834: Excessive Iteration
The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
36 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-67726 — Tornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameters
- CVE-2025-6714 — Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections
- CVE-2024-4227 — gSOAP: Vulnerable to specially crafted unencrypted SDC messages
- CVE-2026-77357 — Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the server
- CVE-2026-59644 — MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
- CVE-2026-50171 — Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
- CVE-2026-64641 — Next.js: Denial of Service in App Router using Server Actions
- CVE-2025-62707 — pypdf affected by possible infinite loop when reading DCT inline images without EOF marker
- CVE-2026-16497 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A s
- CVE-2026-34043 — Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
- CVE-2026-41168 — pypdf has possible long runtimes for wrong size values in cross-reference and object streams
- CVE-2026-45680 — OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
- CVE-2026-40347 — Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data
- CVE-2026-48156 — pypdf: Possible long runtimes for zero-only width values in cross-reference streams
- CVE-2026-84310 — pypdf: Possible long runtimes/large memory usage when retrieving outlines
- CVE-2026-71852 — pypdf: Possible long runtimes/large memory usage for large CID font width ranges
- CVE-2026-84311 — pypdf: Possible long runtimes/large memory usage when extracting XForm objects
- CVE-2026-41313 — pypdf: Possible long runtimes for wrong size values in incremental mode
Recently published
- CVE-2026-16497 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A s
- CVE-2026-84311 — pypdf: Possible long runtimes/large memory usage when extracting XForm objects
- CVE-2026-84310 — pypdf: Possible long runtimes/large memory usage when retrieving outlines
- CVE-2026-77357 — Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the server
- CVE-2026-71852 — pypdf: Possible long runtimes/large memory usage for large CID font width ranges
- CVE-2026-59644 — MLS hash-ratchet honours arbitrary 32-bit generation counter from sender
- CVE-2026-64641 — Next.js: Denial of Service in App Router using Server Actions
- CVE-2026-50171 — Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
- CVE-2026-45680 — OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
- CVE-2026-48156 — pypdf: Possible long runtimes for zero-only width values in cross-reference streams
- CVE-2026-41313 — pypdf: Possible long runtimes for wrong size values in incremental mode
- CVE-2026-41168 — pypdf has possible long runtimes for wrong size values in cross-reference and object streams
- CVE-2026-40347 — Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data
- CVE-2026-34043 — Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
- CVE-2025-67726 — Tornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameters
- CVE-2025-62707 — pypdf affected by possible infinite loop when reading DCT inline images without EOF marker
- CVE-2025-6714 — Incorrect Handling of incomplete data may prevent mongoS from Accepting New Connections
- CVE-2024-4227 — gSOAP: Vulnerable to specially crafted unencrypted SDC messages