CWE-674
Allowed-with-ReviewUncontrolled Recursion
Abstraction: Class · Status: Draft
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
823 vulnerabilities reference this CWE, most recent first.
CVE-2026-104020 (GCVE-0-2026-104020)
Vulnerability from cvelistv5 – Published: 2026-10-01 20:36 – Updated: 2026-10-01 21:07- CWE-674 - Uncontrolled recursion
| URL | Tags |
|---|---|
| https://github.com/amazon-ion/ion-python/releases… | patch |
| https://aws.amazon.com/security/security-bulletin… | vendor-advisory |
| https://github.com/amazon-ion/ion-python/security… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Amazon | ion-python |
Affected:
0 , < 0.15.0
(custom)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ion-python",
"vendor": "Amazon",
"versions": [
{
"lessThan": "0.15.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "University of Manchester"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.\u003c/p\u003e\u003cp\u003eTo remediate this issue, users should upgrade to version 0.15.0 or later.\u003c/p\u003e"
}
],
"value": "Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.\n\n\n\nTo remediate this issue, users should upgrade to version 0.15.0 or later."
}
],
"impacts": [
{
"capecId": "CAPEC-230",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-230 Serialized Data with Nested Payloads"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T21:07:33.567Z",
"orgId": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"shortName": "AMZN"
},
"references": [
{
"tags": [
"patch"
],
"url": "https://github.com/amazon-ion/ion-python/releases/tag/v0.15.0"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://aws.amazon.com/security/security-bulletins/2026-122-aws/"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://github.com/amazon-ion/ion-python/security/advisories/GHSA-93q6-f8hx-vv7f"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Uncontrolled recursion in the Ion reader in Amazon Ion Python",
"x_generator": {
"engine": "Vulnogram 0.5.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "ff89ba41-3aa1-4d27-914a-91399e9639e5",
"assignerShortName": "AMZN",
"cveId": "CVE-2026-104020",
"datePublished": "2026-10-01T20:36:33.967Z",
"dateReserved": "2026-10-01T16:57:41.444Z",
"dateUpdated": "2026-10-01T21:07:33.567Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103118 (GCVE-0-2026-103118)
Vulnerability from cvelistv5 – Published: 2026-09-30 13:30 – Updated: 2026-09-30 13:30 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/411874 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/411874/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103118 | third-party-advisory |
| https://vuldb.com/submit/954970 | third-party-advisory |
| https://foss.heptapod.net/graphicsmagick/graphics… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | GraphicsMagick |
Affected:
1.3.0
Affected: 1.3.1 Affected: 1.3.2 Affected: 1.3.3 Affected: 1.3.4 Affected: 1.3.5 Affected: 1.3.6 Affected: 1.3.7 Affected: 1.3.8 Affected: 1.3.9 Affected: 1.3.10 Affected: 1.3.11 Affected: 1.3.12 Affected: 1.3.13 Affected: 1.3.14 Affected: 1.3.15 Affected: 1.3.16 Affected: 1.3.17 Affected: 1.3.18 Affected: 1.3.19 Affected: 1.3.20 Affected: 1.3.21 Affected: 1.3.22 Affected: 1.3.23 Affected: 1.3.24 Affected: 1.3.25 Affected: 1.3.26 Affected: 1.3.27 Affected: 1.3.28 Affected: 1.3.29 Affected: 1.3.30 Affected: 1.3.31 Affected: 1.3.32 Affected: 1.3.33 Affected: 1.3.34 Affected: 1.3.35 Affected: 1.3.36 Affected: 1.3.37 Affected: 1.3.38 Affected: 1.3.39 Affected: 1.3.40 Affected: 1.3.41 Affected: 1.3.42 Affected: 1.3.43 Affected: 1.3.44 Affected: 1.3.45 Affected: 1.3.46 Affected: 1.3.47 cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:graphicsmagick:graphicsmagick:*:*:*:*:*:*:*:*"
],
"modules": [
"WPG File Handler"
],
"product": "GraphicsMagick",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "1.3.0"
},
{
"status": "affected",
"version": "1.3.1"
},
{
"status": "affected",
"version": "1.3.2"
},
{
"status": "affected",
"version": "1.3.3"
},
{
"status": "affected",
"version": "1.3.4"
},
{
"status": "affected",
"version": "1.3.5"
},
{
"status": "affected",
"version": "1.3.6"
},
{
"status": "affected",
"version": "1.3.7"
},
{
"status": "affected",
"version": "1.3.8"
},
{
"status": "affected",
"version": "1.3.9"
},
{
"status": "affected",
"version": "1.3.10"
},
{
"status": "affected",
"version": "1.3.11"
},
{
"status": "affected",
"version": "1.3.12"
},
{
"status": "affected",
"version": "1.3.13"
},
{
"status": "affected",
"version": "1.3.14"
},
{
"status": "affected",
"version": "1.3.15"
},
{
"status": "affected",
"version": "1.3.16"
},
{
"status": "affected",
"version": "1.3.17"
},
{
"status": "affected",
"version": "1.3.18"
},
{
"status": "affected",
"version": "1.3.19"
},
{
"status": "affected",
"version": "1.3.20"
},
{
"status": "affected",
"version": "1.3.21"
},
{
"status": "affected",
"version": "1.3.22"
},
{
"status": "affected",
"version": "1.3.23"
},
{
"status": "affected",
"version": "1.3.24"
},
{
"status": "affected",
"version": "1.3.25"
},
{
"status": "affected",
"version": "1.3.26"
},
{
"status": "affected",
"version": "1.3.27"
},
{
"status": "affected",
"version": "1.3.28"
},
{
"status": "affected",
"version": "1.3.29"
},
{
"status": "affected",
"version": "1.3.30"
},
{
"status": "affected",
"version": "1.3.31"
},
{
"status": "affected",
"version": "1.3.32"
},
{
"status": "affected",
"version": "1.3.33"
},
{
"status": "affected",
"version": "1.3.34"
},
{
"status": "affected",
"version": "1.3.35"
},
{
"status": "affected",
"version": "1.3.36"
},
{
"status": "affected",
"version": "1.3.37"
},
{
"status": "affected",
"version": "1.3.38"
},
{
"status": "affected",
"version": "1.3.39"
},
{
"status": "affected",
"version": "1.3.40"
},
{
"status": "affected",
"version": "1.3.41"
},
{
"status": "affected",
"version": "1.3.42"
},
{
"status": "affected",
"version": "1.3.43"
},
{
"status": "affected",
"version": "1.3.44"
},
{
"status": "affected",
"version": "1.3.45"
},
{
"status": "affected",
"version": "1.3.46"
},
{
"status": "affected",
"version": "1.3.47"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "zzxzzb (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-404",
"description": "Denial of Service",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:30:05.945Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-411874 | GraphicsMagick WPG File wpg.c ExtractPostscript recursion",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/411874"
},
{
"name": "VDB-411874 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/411874/cti"
},
{
"name": "CVE-2026-103118 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103118"
},
{
"name": "Submit #954970 | Graphicsmagick 1.3.47 and prior; fixed in development changeset 627b5b1b2fc2 (2026-08-24), not yet in any release Uncontrolled Recursion",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/954970"
},
{
"tags": [
"patch"
],
"url": "https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T08:02:10.000Z",
"value": "VulDB entry last update"
}
],
"title": "GraphicsMagick WPG File wpg.c ExtractPostscript recursion",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103118",
"datePublished": "2026-09-30T13:30:05.945Z",
"dateReserved": "2026-09-30T05:57:03.831Z",
"dateUpdated": "2026-09-30T13:30:05.945Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103087 (GCVE-0-2026-103087)
Vulnerability from cvelistv5 – Published: 2026-09-30 00:35 – Updated: 2026-09-30 19:08 X_Open Source- CWE-674 - Uncontrolled Recursion
| URL | Tags |
|---|---|
| https://github.com/gosub-io/gosub-engine/security… | vendor-advisory |
| https://github.com/gosub-io/gosub-engine/pull/1229 | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| gosub-io | gosub-engine |
Affected:
0 , < 46868b3deae44544bee2a13e756772966dde950e
(git)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103087",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T18:50:01.779392Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T19:08:33.809Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "gosub-engine",
"repo": "https://github.com/gosub-io/gosub-engine",
"vendor": "gosub-io",
"versions": [
{
"lessThan": "46868b3deae44544bee2a13e756772966dde950e",
"status": "affected",
"version": "0",
"versionType": "git"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T00:35:06.196Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp"
},
{
"tags": [
"patch"
],
"url": "https://github.com/gosub-io/gosub-engine/pull/1229"
}
],
"tags": [
"x_open-source"
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-103087",
"datePublished": "2026-09-30T00:35:06.196Z",
"dateReserved": "2026-09-30T00:35:05.437Z",
"dateUpdated": "2026-09-30T19:08:33.809Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102510 (GCVE-0-2026-102510)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:01 – Updated: 2026-09-30 14:40- CWE-789 - Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)
- CWE-190 - Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)
- CWE-129 - Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)
- CWE-674 - Uncontrolled Recursion. This covers the Go part of f045
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/lw66k49p1jf7… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.11.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102510",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:40:24.270117Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:31.604Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://golang.org/pkg",
"defaultStatus": "unaffected",
"packageName": "github.com/apache/plc4x/plc4go",
"packageURL": "pkg:golang/github.com/apache/plc4x/plc4go",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.11.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eInteger Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\u003cbr\u003ecausing a denial of service.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\u003cbr\u003e- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\u003cbr\u003e- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\u003cbr\u003e- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102509\"\u003eCVE-2026-102509\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \u003cbr\u003eadditional, independent protocol messages.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the array pre-allocation (f017) and the transport read buffers (f018)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-190",
"description": "CWE-190 Integer Overflow or Wraparound. This covers the uint16 length and position wraps (f009) and the EIP packet size wrapping to 0 (f014)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-129",
"description": "CWE-129 Improper Validation of Array Index. This covers the ADS and KNXnet/IP index panics (f013, f015)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the Go part of f045",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:01:43.024Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs"
}
],
"source": {
"discovery": "INTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T12:16:00.000Z",
"value": "found during the internal security review"
},
{
"lang": "en",
"time": "2026-09-07T12:17:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-controlled lengths",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102510",
"datePublished": "2026-09-30T08:01:43.024Z",
"dateReserved": "2026-09-29T11:41:34.033Z",
"dateUpdated": "2026-09-30T14:40:31.604Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102509 (GCVE-0-2026-102509)
Vulnerability from cvelistv5 – Published: 2026-09-30 08:00 – Updated: 2026-09-30 14:40- CWE-789 - Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).
- CWE-770 - Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).
- CWE-674 - Uncontrolled Recursion. This covers the nested mspec types (f045).
| URL | Tags |
|---|---|
| https://lists.apache.org/thread.html/qngc85qhnlj7… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache PLC4X |
Affected:
0.10.0 , < 1.0.0
(semver)
Unaffected: 1.0.0 (semver) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102509",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:39:55.913450Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:40:06.881Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-spi",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-spi",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.plc4x:plc4j-driver-opcua",
"packageURL": "pkg:maven/org.apache.plc4x/plc4j-driver-opcua",
"product": "Apache PLC4X",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThan": "1.0.0",
"status": "affected",
"version": "0.10.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Abhinav Agarwal"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cdiv\u003e\u003cpre\u003eMemory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\u003cbr\u003e\u003cbr\u003eIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \u003cbr\u003eimpersonate it.\u003cbr\u003e\u003cbr\u003eThe individual defects are:\u003cbr\u003e- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\u003cbr\u003e- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\u003cbr\u003e- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\u003cbr\u003e- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by \u003ca href=\"https://cveprocess.apache.org/cve5/CVE-2026-102510\"\u003eCVE-2026-102510\u003c/a\u003e.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\u003cbr\u003e\u003cbr\u003eUsers are recommended to upgrade to version 1.0.0, which fixes the issue.\u003c/pre\u003e\u003c/div\u003e"
}
],
"value": "Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\n\nIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server\u0027s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \nimpersonate it.\n\nThe individual defects are:\n- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\n- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\n- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\n- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .\n\nThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-789",
"description": "CWE-789 Memory Allocation with Excessive Size Value. This covers the byte strings (F2), the array counts (F4) and the element counts (f024).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "CWE-770 Allocation of Resources Without Limits or Throttling. This covers the chunk accumulation (F3).",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674 Uncontrolled Recursion. This covers the nested mspec types (f045).",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T08:00:27.709Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread.html/qngc85qhnlj7kpk3z58z0xlxhz2tn6gp"
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-07-09T12:11:00.000Z",
"value": "reported to the Apache Security Team"
},
{
"lang": "en",
"time": "2026-07-10T12:11:00.000Z",
"value": "reported issues fixed on develop (a2dbb6bfc0, 5a4d5bdb4c)"
},
{
"lang": "en",
"time": "2026-09-07T12:12:00.000Z",
"value": "Apache PLC4X 1.0.0 released with the fixes"
}
],
"title": "Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-102509",
"datePublished": "2026-09-30T08:00:27.709Z",
"dateReserved": "2026-09-29T11:41:21.875Z",
"dateUpdated": "2026-09-30T14:40:06.881Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102281 (GCVE-0-2026-102281)
Vulnerability from cvelistv5 – Published: 2026-09-28 21:21 – Updated: 2026-09-29 12:50| URL | Tags |
|---|---|
| https://github.com/nestjs/nest/security/advisorie… | x_refsource_CONFIRM |
| https://github.com/nestjs/nest/pull/17737 | x_refsource_MISC |
| https://github.com/nestjs/nest/commit/aa97b5144d8… | x_refsource_MISC |
| https://github.com/nestjs/nest/commit/e9dcd4c7ac6… | x_refsource_MISC |
| https://github.com/nestjs/nest/releases/tag/v11.2.4 | x_refsource_MISC |
| https://github.com/nestjs/nest/releases/tag/v12.0.2 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102281",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T12:49:43.038730Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T12:50:34.126Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/nestjs/nest/security/advisories/GHSA-m8vh-jmq9-5rjg"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "nest",
"vendor": "nestjs",
"versions": [
{
"status": "affected",
"version": "\u003c 11.2.4"
},
{
"status": "affected",
"version": "\u003e= 12.0.0, \u003c 12.0.2"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a client-controlled non-string pattern to JSON.stringify to derive the handler lookup key; sufficiently deep nesting throws RangeError: Maximum call stack size exceeded, and the unhandled promise rejection terminates Node.js under its default behavior. An attacker who can reach the TCP port or publish to the consumed RabbitMQ queue or exchange can crash the service on demand; other transports are not affected because their patterns arrive as strings. This issue is fixed in versions 11.2.4 and 12.0.2."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-248",
"description": "CWE-248: Uncaught Exception",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T21:21:25.047Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/nestjs/nest/security/advisories/GHSA-m8vh-jmq9-5rjg",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/nestjs/nest/security/advisories/GHSA-m8vh-jmq9-5rjg"
},
{
"name": "https://github.com/nestjs/nest/pull/17737",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nestjs/nest/pull/17737"
},
{
"name": "https://github.com/nestjs/nest/commit/aa97b5144d8dff1ce700aac521eb86449a679d6f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nestjs/nest/commit/aa97b5144d8dff1ce700aac521eb86449a679d6f"
},
{
"name": "https://github.com/nestjs/nest/commit/e9dcd4c7ac64361fbfe79461da85f5b3fc3e02da",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nestjs/nest/commit/e9dcd4c7ac64361fbfe79461da85f5b3fc3e02da"
},
{
"name": "https://github.com/nestjs/nest/releases/tag/v11.2.4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nestjs/nest/releases/tag/v11.2.4"
},
{
"name": "https://github.com/nestjs/nest/releases/tag/v12.0.2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nestjs/nest/releases/tag/v12.0.2"
}
],
"source": {
"advisory": "GHSA-m8vh-jmq9-5rjg",
"discovery": "UNKNOWN"
},
"title": "Nest: Remote process termination via a deeply nested microservice message pattern"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102281",
"datePublished": "2026-09-28T21:21:25.047Z",
"dateReserved": "2026-09-28T20:11:16.659Z",
"dateUpdated": "2026-09-29T12:50:34.126Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102278 (GCVE-0-2026-102278)
Vulnerability from cvelistv5 – Published: 2026-09-28 20:57 – Updated: 2026-10-01 15:02| URL | Tags |
|---|---|
| https://github.com/juliangruber/brace-expansion/s… | x_refsource_CONFIRM |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| juliangruber | brace-expansion |
Affected:
>= 4.0.0, < 5.0.11
Affected: >= 3.0.0, < 3.0.8 Affected: >= 2.0.0, < 2.1.6 Affected: < 1.1.20 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102278",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:02:35.975978Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:02:44.798Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "brace-expansion",
"vendor": "juliangruber",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.0.0, \u003c 5.0.11"
},
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.0.8"
},
{
"status": "affected",
"version": "\u003e= 2.0.0, \u003c 2.1.6"
},
{
"status": "affected",
"version": "\u003c 1.1.20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:57:09.850Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"
}
],
"source": {
"advisory": "GHSA-qhr7-859c-m2p7",
"discovery": "UNKNOWN"
},
"title": "brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102278",
"datePublished": "2026-09-28T20:57:09.850Z",
"dateReserved": "2026-09-28T20:11:16.659Z",
"dateUpdated": "2026-10-01T15:02:44.798Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102276 (GCVE-0-2026-102276)
Vulnerability from cvelistv5 – Published: 2026-09-28 20:50 – Updated: 2026-09-29 13:38| URL | Tags |
|---|---|
| https://github.com/juliangruber/brace-expansion/s… | x_refsource_CONFIRM |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| https://github.com/juliangruber/brace-expansion/c… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| juliangruber | brace-expansion |
Affected:
>= 4.0.0, < 5.0.10
Affected: >= 3.0.0, < 3.0.7 Affected: >= 2.0.0, < 2.1.5 Affected: < 1.1.19 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102276",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T13:37:06.086529Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T13:38:29.919Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "brace-expansion",
"vendor": "juliangruber",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.0.0, \u003c 5.0.10"
},
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.0.7"
},
{
"status": "affected",
"version": "\u003e= 2.0.0, \u003c 2.1.5"
},
{
"status": "affected",
"version": "\u003c 1.1.19"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:50:59.984Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc"
},
{
"name": "https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"
}
],
"source": {
"advisory": "GHSA-6j4f-fj2g-mc7p",
"discovery": "UNKNOWN"
},
"title": "brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102276",
"datePublished": "2026-09-28T20:50:59.984Z",
"dateReserved": "2026-09-28T20:11:16.658Z",
"dateUpdated": "2026-09-29T13:38:29.919Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-102265 (GCVE-0-2026-102265)
Vulnerability from cvelistv5 – Published: 2026-09-28 20:48 – Updated: 2026-10-01 15:01- CWE-674 - Uncontrolled Recursion
| URL | Tags |
|---|---|
| https://github.com/jpadilla/pyjwt/security/adviso… | x_refsource_CONFIRM |
| https://github.com/jpadilla/pyjwt/commit/06573692… | x_refsource_MISC |
| https://github.com/jpadilla/pyjwt/releases/tag/2.14.0 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-102265",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:00:55.850520Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:01:31.377Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "pyjwt",
"vendor": "jpadilla",
"versions": [
{
"status": "affected",
"version": "\u003e= 2.13.0, \u003c 2.14.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "CWE-674: Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T20:48:04.664Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863"
},
{
"name": "https://github.com/jpadilla/pyjwt/commit/06573692ebcdec8831c3927513b3e87c31fbbb62",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/jpadilla/pyjwt/commit/06573692ebcdec8831c3927513b3e87c31fbbb62"
},
{
"name": "https://github.com/jpadilla/pyjwt/releases/tag/2.14.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"
}
],
"source": {
"advisory": "GHSA-8wjv-2p76-3863",
"discovery": "UNKNOWN"
},
"title": "PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-102265",
"datePublished": "2026-09-28T20:48:04.664Z",
"dateReserved": "2026-09-28T20:11:16.658Z",
"dateUpdated": "2026-10-01T15:01:31.377Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100702 (GCVE-0-2026-100702)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:23 – Updated: 2026-09-26 23:11- CWE-674 - Uncontrolled Recursion
| URL | Tags |
|---|---|
| https://github.com/nodemailer/nodemailer/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/nodemailer-b… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| nodemailer | nodemailer |
Affected:
0 , < 10.0.2
(semver)
Unaffected: 10.0.2 (semver) cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100702",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-26T23:11:09.180121Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T23:11:16.551Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/nodemailer",
"product": "nodemailer",
"vendor": "nodemailer",
"versions": [
{
"lessThan": "10.0.2",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "10.0.2",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodemailer:nodemailer:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ry2811"
}
],
"datePublic": "2026-09-10T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the Node.js process."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-674",
"description": "Uncontrolled Recursion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T13:23:57.945Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8vvx-rff5-p5rq)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq"
},
{
"name": "VulnCheck Advisory: Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/nodemailer-before-10.0.2-stack-exhaustion-via-nested-recipient-arrays"
}
],
"title": "Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100702",
"datePublished": "2026-09-26T13:23:57.945Z",
"dateReserved": "2026-09-26T02:39:50.973Z",
"dateUpdated": "2026-09-26T23:11:16.551Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Ensure that an end condition will be reached under all logic conditions. The end condition may include checking against the depth of recursion and exiting with an error if the recursion goes too deep. The complexity of the end condition contributes to the effectiveness of this action.
Mitigation
Increase the stack size.
CAPEC-230: Serialized Data with Nested Payloads
Applications often need to transform data in and out of a data format (e.g., XML and YAML) by using a parser. It may be possible for an adversary to inject data that may have an adverse effect on the parser when it is being processed. Many data format languages allow the definition of macro-like structures that can be used to simplify the creation of complex structures. By nesting these structures, causing the data to be repeatedly substituted, an adversary can cause the parser to consume more resources while processing, causing excessive memory consumption and CPU utilization.
CAPEC-231: Oversized Serialized Data Payloads
An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon the parser such as exhausting system resources and arbitrary code execution.