CWE-835: Infinite Loop
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
327 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-24816 — Cookie Security Vulnerabilities in datavane/tis
- CVE-2026-24804 — A infinite loop vulnerability in coolsnowwolf/lede
- CVE-2026-24803 — A possible infinite loop vulnerability in coolsnowwolf/lede
- CVE-2025-55118 — BMC Control-M/Agent memory corruption in SSL/TLS communication
- CVE-2026-21905 — Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash
- CVE-2025-7054 — Infinite loop triggered by connection ID retirement
- CVE-2025-3857 — Infinite loop condition in Amazon.IonDotnet
- CVE-2025-29776 — Azle calling `setTimer` causes infinite loop of timers
- CVE-2025-27497 — OpenDJ Denial of Service (Dos) using alias loop
- CVE-2025-20253 — Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability
- CVE-2025-20243 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
- CVE-2025-20217 — Cisco Firepower Threat Defense Intrusion Detection Denial of Service Vulnerability
- CVE-2025-20136 — Cisco Adaptive Security Appliance and Firepower Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability
- CVE-2025-68137 — EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
- CVE-2025-66252 — Infinite Loop Denial of Service via Failed File Deletion
- CVE-2026-33013 — Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
- CVE-2025-2962 — Infinite loop in dns_copy_qname
- CVE-2024-0211 — Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
- CVE-2025-20312 — A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe
- CVE-2026-4645 — A flaw was found in the `github.com/antchfx/xpath` component. A remote attacker could exploit this vulnerability by subm
Recently published
- CVE-2026-88002 — Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
- CVE-2026-88000 — Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
- CVE-2026-87013 — Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
- CVE-2026-6554 — infinte loop in libpcap before 1.10.7
- CVE-2026-85730 — smol-toml: Denial of Service via malformed TOML documents
- CVE-2026-78543 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-84309 — pypdf: Possible infinite loop for TreeObject.insert_child
- CVE-2026-82605 — BareBones BBEdit Lasso Language Tokenizer infinite loop
- CVE-2026-82579 — AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service
- CVE-2025-10903 — Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab
- CVE-2026-55588 — ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
- CVE-2026-55373 — OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MAX sample counts
- CVE-2026-78250 — bytebot-ai bytebot Agent Execution Workflow infinite loop
- CVE-2026-45271 — picotls has infinite recursion in the minicrypto ASN.1 decoder
- CVE-2026-54623 — django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
- CVE-2026-61556 — LiquidJS: An infinite loop vulnerability in `strip_html` filter
- CVE-2026-12629 — PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service
- CVE-2026-68762 — In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
- CVE-2026-13002 — Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
- CVE-2026-17004 — IBM i is Affected By Multiple Vulnerabilities in Host Servers