CWE-606
AllowedUnchecked Input for Loop Condition
Abstraction: Base · Status: Draft
The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
79 vulnerabilities reference this CWE, most recent first.
GHSA-39W3-FG6Q-3VW3
Vulnerability from github – Published: 2026-03-10 18:31 – Updated: 2026-03-10 18:31Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.
{
"affected": [],
"aliases": [
"CVE-2026-27689"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-03-10T17:38:11Z",
"severity": "HIGH"
},
"details": "Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.",
"id": "GHSA-39w3-fg6q-3vw3",
"modified": "2026-03-10T18:31:17Z",
"published": "2026-03-10T18:31:17Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27689"
},
{
"type": "WEB",
"url": "https://me.sap.com/notes/3719502"
},
{
"type": "WEB",
"url": "https://url.sap/sapsecuritypatchday"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-3P3X-VG38-6G9Q
Vulnerability from github – Published: 2023-07-19 12:31 – Updated: 2024-06-10 18:30Issue summary: Checking excessively long DH keys or parameters may be very slow.
Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service.
The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length.
However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large.
An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Denial of Service attack.
The function DH_check() is itself called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_ex() and EVP_PKEY_param_check().
Also vulnerable are the OpenSSL dhparam and pkeyparam command line applications when using the '-check' option.
The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
{
"affected": [],
"aliases": [
"CVE-2023-3446"
],
"database_specific": {
"cwe_ids": [
"CWE-1333",
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-19T12:15:10Z",
"severity": "MODERATE"
},
"details": "Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. One of those\nchecks confirms that the modulus (\u0027p\u0027 parameter) is not too large. Trying to use\na very large modulus is slow and OpenSSL will not normally use a modulus which\nis over 10,000 bits in length.\n\nHowever the DH_check() function checks numerous aspects of the key or parameters\nthat have been supplied. Some of those checks use the supplied modulus value\neven if it has already been found to be too large.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulernable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the \u0027-check\u0027 option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.",
"id": "GHSA-3p3x-vg38-6g9q",
"modified": "2024-06-10T18:30:45Z",
"published": "2023-07-19T12:31:02Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3446"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202402-08"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230803-0011"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20230719.txt"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/19/4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/19/5"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/19/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/31/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/05/16/1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-4279-Q6MJ-392R
Vulnerability from github – Published: 2026-06-03 00:30 – Updated: 2026-09-17 12:31(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.
{
"affected": [],
"aliases": [
"CVE-2026-27145"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-06-02T23:16:35Z",
"severity": "MODERATE"
},
"details": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname\u0027s label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.",
"id": "GHSA-4279-q6mj-392r",
"modified": "2026-09-17T12:31:59Z",
"published": "2026-06-03T00:30:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:59557"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:59556"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:57649"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:57488"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:57482"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:57194"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:55899"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54757"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54603"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54531"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54525"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54500"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54441"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54435"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54432"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54427"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54401"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:54168"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53530"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53416"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53415"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53413"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53412"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:53374"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:52946"
},
{
"type": "WEB",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2026-5037"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"
},
{
"type": "WEB",
"url": "https://go.dev/issue/79694"
},
{
"type": "WEB",
"url": "https://go.dev/cl/783621"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2026-27145"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:68335"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:68334"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:66022"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:63016"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:61314"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:61253"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60391"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60390"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60388"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60387"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60386"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60354"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60315"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:60025"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:59593"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:59579"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:59559"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:59558"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42080"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42079"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42051"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42050"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42049"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42047"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42043"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:41930"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:41036"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:41030"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:39879"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:39573"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:39005"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:38995"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:36797"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:36648"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:36317"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:35832"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:34359"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:34357"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:33574"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:29981"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:29980"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:23264"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:23262"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:51187"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:51057"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:50319"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:50205"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49770"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49765"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49744"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49729"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49712"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49705"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49703"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:49702"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:47737"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:47735"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:47149"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:46395"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:46394"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:44622"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42946"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42644"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42240"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42151"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42150"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42142"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:42082"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-45FX-QQ48-M87M
Vulnerability from github – Published: 2026-07-08 21:30 – Updated: 2026-07-08 21:30FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
{
"affected": [],
"aliases": [
"CVE-2026-15172"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-08T21:16:48Z",
"severity": "MODERATE"
},
"details": "FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service",
"id": "GHSA-45fx-qq48-m87m",
"modified": "2026-07-08T21:30:30Z",
"published": "2026-07-08T21:30:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15172"
},
{
"type": "WEB",
"url": "https://gitlab.com/wireshark/wireshark/-/work_items/21347"
},
{
"type": "WEB",
"url": "https://www.wireshark.org/security/wnpa-sec-2026-54.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-472F-2V5J-FH75
Vulnerability from github – Published: 2026-06-09 09:32 – Updated: 2026-06-09 09:32Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.
{
"affected": [],
"aliases": [
"CVE-2026-41986"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-06-09T08:16:28Z",
"severity": "LOW"
},
"details": "Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.",
"id": "GHSA-472f-2v5j-fh75",
"modified": "2026-06-09T09:32:06Z",
"published": "2026-06-09T09:32:06Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41986"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletin/2026/6"
},
{
"type": "WEB",
"url": "https://consumer.huawei.com/en/support/bulletinlaptops/2026/6"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-48R3-MR49-JP8X
Vulnerability from github – Published: 2026-08-25 15:33 – Updated: 2026-08-25 15:33GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.
This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
{
"affected": [],
"aliases": [
"CVE-2026-16599"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-25T15:16:30Z",
"severity": "MODERATE"
},
"details": "GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa",
"id": "GHSA-48r3-mr49-jp8x",
"modified": "2026-08-25T15:33:00Z",
"published": "2026-08-25T15:33:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16599"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2026/08/CVE-2026-16599"
},
{
"type": "WEB",
"url": "https://gitlab.com/gnuwget/wget"
},
{
"type": "WEB",
"url": "https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-4F32-Q83J-5VFJ
Vulnerability from github – Published: 2025-05-07 09:31 – Updated: 2025-05-07 09:31An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to enter an infinite loop by sending a malicious RPC packet.
{
"affected": [],
"aliases": [
"CVE-2025-32399"
],
"database_specific": {
"cwe_ids": [
"CWE-1284",
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-07T07:15:50Z",
"severity": "MODERATE"
},
"details": "An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to enter an infinite loop by sending a malicious RPC packet.",
"id": "GHSA-4f32-q83j-5vfj",
"modified": "2025-05-07T09:31:17Z",
"published": "2025-05-07T09:31:17Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32399"
},
{
"type": "WEB",
"url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-32399"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-4J92-6H2X-83RF
Vulnerability from github – Published: 2026-08-05 09:31 – Updated: 2026-08-06 18:30An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.
{
"affected": [],
"aliases": [
"CVE-2026-68077"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-05T07:16:39Z",
"severity": "MODERATE"
},
"details": "An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.",
"id": "GHSA-4j92-6h2x-83rf",
"modified": "2026-08-06T18:30:36Z",
"published": "2026-08-05T09:31:15Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68077"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/gzc78gdrlw2711v8jzgmsto8bqvg28y8"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2026/08/04/18"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-5FCG-GPH2-WCVG
Vulnerability from github – Published: 2025-05-22 18:31 – Updated: 2025-05-22 18:31An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
{
"affected": [],
"aliases": [
"CVE-2024-13930"
],
"database_specific": {
"cwe_ids": [
"CWE-606"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-22T18:15:39Z",
"severity": "MODERATE"
},
"details": "An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised\nThis issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.",
"id": "GHSA-5fcg-gph2-wcvg",
"modified": "2025-05-22T18:31:16Z",
"published": "2025-05-22T18:31:16Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13930"
},
{
"type": "WEB",
"url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A0021\u0026LanguageCode=en\u0026DocumentPartId=pdf\u0026Action=Launch"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-64FM-8HW2-V72W
Vulnerability from github – Published: 2024-03-25 19:38 – Updated: 2026-02-05 15:26Impact
KaTeX users who render untrusted mathematical expressions could encounter malicious input using \edef that causes a near-infinite loop, despite setting maxExpand to avoid such loops. This can be used as an availability attack, where e.g. a client rendering another user's KaTeX input will be unable to use the site due to memory overflow, tying up the main thread, or stack overflow.
Patches
Upgrade to KaTeX v0.16.10 to remove this vulnerability.
Workarounds
Forbid inputs containing the substring "\\edef" before passing them to KaTeX.
(There is no easy workaround for the auto-render extension.)
Details
KaTeX supports an option named maxExpand which prevents infinitely recursive macros from consuming all available memory and/or triggering a stack overflow error. However, what counted as an "expansion" is a single macro expanding to any number of tokens. The expand-and-define TeX command \edef can be used to build up an exponential number of tokens using only a linear number of expansions according to this definition, e.g. by repeatedly doubling the previous definition. This has been corrected in KaTeX v0.16.10, where every expanded token in an \edef counts as an expansion.
For more information
If you have any questions or comments about this advisory: * Open an issue or security advisory in the KaTeX repository * Email us at katex-security@mit.edu
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "katex"
},
"ranges": [
{
"events": [
{
"introduced": "0.12.0"
},
{
"fixed": "0.16.10"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2024-28243"
],
"database_specific": {
"cwe_ids": [
"CWE-606",
"CWE-674"
],
"github_reviewed": true,
"github_reviewed_at": "2024-03-25T19:38:18Z",
"nvd_published_at": "2024-03-25T20:15:07Z",
"severity": "MODERATE"
},
"details": "### Impact\nKaTeX users who render untrusted mathematical expressions could encounter malicious input using `\\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. This can be used as an availability attack, where e.g. a client rendering another user\u0027s KaTeX input will be unable to use the site due to memory overflow, tying up the main thread, or stack overflow.\n\n### Patches\nUpgrade to KaTeX v0.16.10 to remove this vulnerability.\n\n### Workarounds\nForbid inputs containing the substring `\"\\\\edef\"` before passing them to KaTeX.\n(There is no easy workaround for the auto-render extension.)\n\n### Details\nKaTeX supports an option named `maxExpand` which prevents infinitely recursive macros from consuming all available memory and/or triggering a stack overflow error. However, what counted as an \"expansion\" is a single macro expanding to any number of tokens. The expand-and-define TeX command `\\edef` can be used to build up an exponential number of tokens using only a linear number of expansions according to this definition, e.g. by repeatedly doubling the previous definition. This has been corrected in KaTeX v0.16.10, where every expanded token in an `\\edef` counts as an expansion.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue or security advisory in the [KaTeX repository](https://github.com/KaTeX/KaTeX/)\n* Email us at [katex-security@mit.edu](mailto:katex-security@mit.edu)",
"id": "GHSA-64fm-8hw2-v72w",
"modified": "2026-02-05T15:26:49Z",
"published": "2024-03-25T19:38:18Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/KaTeX/KaTeX/security/advisories/GHSA-64fm-8hw2-v72w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28243"
},
{
"type": "WEB",
"url": "https://github.com/github/advisory-database/pull/6777"
},
{
"type": "WEB",
"url": "https://github.com/KaTeX/KaTeX/commit/e88b4c357f978b1bca8edfe3297f0aa309bcbe34"
},
{
"type": "PACKAGE",
"url": "https://github.com/KaTeX/KaTeX"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "KaTeX\u0027s maxExpand bypassed by `\\edef`"
}
Mitigation
Do not use user-controlled data for loop conditions.
Mitigation
Perform input validation.
No CAPEC attack patterns related to this CWE.