CWE-835— Loop with Unreachable Exit Condition (Infinite Loop)
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.— MITRE CWE catalog
981 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-835page 4 of 20
- CVE-2025-69227HIGHCVSS 7.5EG 7.52026-01-06
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS attack when processing a POST body. If op…
- CVE-2025-66252HIGHCVSS 7.5EG 7.52025-11-26
Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Infinite loop when u…
- CVE-2025-41075HIGHCVSS 7.5EG 7.52025-11-20
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resourc…
- CVE-2025-41074HIGHCVSS 7.5EG 7.52025-11-20
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resour…
- CVE-2025-63829HIGHCVSS 7.5EG 7.52025-11-18
eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function.
- CVE-2025-51986HIGHCVSS 7.5EG 7.52025-08-14
An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via a crafted length value for a packet.
- CVE-2025-8194HIGHCVSS 7.5EG 7.52025-07-28
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop a…
- CVE-2025-53015HIGHCVSS 7.5EG 7.52025-07-14
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
- CVE-2025-2962HIGHCVSS 7.5EG 7.52025-06-24
A denial-of-service issue in the dns implemenation could cause an infinite loop.
- CVE-2025-6365HIGHCVSS 7.5EG 7.52025-06-20
A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the function set_pte_at in the library /include/arch-arm64/pgtable.h. The manipulation leads…
- CVE-2025-0673HIGHCVSS 7.5EG 7.52025-06-12
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service …
- CVE-2025-30145HIGHCVSS 7.5EG 7.52025-06-10
GeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either as a rendering transformation in WMS dynamic styles or as a WPS process, that can enter a…
- CVE-2025-5399HIGHCVSS 7.5EG 7.52025-06-07
Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other t…
- CVE-2024-22654HIGHCVSS 7.5EG 7.52025-05-29
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
- CVE-2025-3857HIGHCVSS 7.5EG 7.52025-04-21
When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed …
- CVE-2025-32947HIGHCVSS 7.5EG 7.52025-04-15
This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities.
- CVE-2025-71319HIGHCVSS 7.5EG 7.52025-04-02
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-ty…
- CVE-2024-9340HIGHCVSS 7.5EG 7.52025-03-20
A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of mult…
- CVE-2024-12704HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the llm using a thread and retrieves the result via the ge…
- CVE-2024-10907HIGHCVSS 7.5EG 7.52025-03-20
In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the…
- CVE-2024-10829HIGHCVSS 7.5EG 7.52025-03-20
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive cha…
- CVE-2024-10821HIGHCVSS 7.5EG 7.52025-03-20
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle ex…
- CVE-2024-40675HIGHCVSS 7.5EG 7.52025-01-28
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2024-11941HIGHCVSS 7.5EG 7.52024-12-05
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.
- CVE-2024-53980HIGHCVSS 7.5EG 7.52024-11-29
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A malicious actor can send a IEEE 802.15.4 packet with spoofed length byte and opti…
- CVE-2024-50321HIGHCVSS 7.5EG 7.52024-11-12
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
- CVE-2024-50319HIGHCVSS 7.5EG 7.52024-11-12
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
- CVE-2024-52532HIGHCVSS 7.5EG 7.52024-11-11
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.
- CVE-2024-45692HIGHCVSS 7.5EG 7.52024-09-04
Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.
- CVE-2024-45506HIGHCVSS 7.5EG 7.52024-09-04
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.
- CVE-2024-43366HIGHCVSS 7.5EG 7.52024-08-15
zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much more late exit condition. It leads to a loss of funds or other …
- CVE-2024-23352HIGHCVSS 7.5EG 7.52024-08-05
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
- CVE-2024-40060HIGHCVSS 7.5EG 7.52024-07-23
go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
- CVE-2024-6227HIGHCVSS 7.5EG 7.52024-07-08
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to res…
- CVE-2024-36732HIGHCVSS 7.5EG 7.52024-06-06
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.
- CVE-2024-32976HIGHCVSS 7.5EG 7.52024-06-04
Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.
- CVE-2024-34489HIGHCVSS 7.5EG 7.52024-05-05
OFPHello in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via length=0.
- CVE-2024-34488HIGHCVSS 7.5EG 7.52024-05-05
OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via b.length=0.
- CVE-2024-34487HIGHCVSS 7.5EG 7.52024-05-05
OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.
- CVE-2024-30251HIGHCVSS 7.5EG 7.52024-05-02
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter a…
- CVE-2024-32650HIGHCVSS 7.5EG 7.52024-04-19
Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately aft…
- CVE-2024-28732HIGHCVSS 7.5EG 7.52024-04-08
An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).
- CVE-2024-24746HIGHCVSS 7.5EG 7.52024-04-06
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affect…
- CVE-2024-29904HIGHCVSS 7.5EG 7.52024-03-29
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7…
- CVE-2024-1931HIGHCVSS 7.5EG 7.52024-03-07
NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE re…
- CVE-2024-27359HIGHCVSS 7.5EG 7.52024-02-26
Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and …
- CVE-2023-51890HIGHCVSS 7.5EG 7.52024-01-24
An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.
- CVE-2023-45233HIGHCVSS 7.5EG 7.52024-01-16
EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially l…
- CVE-2023-45232HIGHCVSS 7.5EG 7.52024-01-16
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentiall…
- CVE-2023-43511HIGHCVSS 7.5EG 7.52024-01-02
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
Map vulnerabilities like CWE-835 to your infrastructure
EchelonGraph correlates every CVE — across CWE-835 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →