Common Weakness Enumeration

CWE-674

Allowed-with-Review

Uncontrolled Recursion

Abstraction: Class · Status: Draft

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

876 vulnerabilities reference this CWE, most recent first.

GHSA-397J-7MPF-RM74

Vulnerability from github – Published: 2022-05-13 01:49 – Updated: 2022-05-13 01:49
VLAI
Details

An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file, a related issue to CVE-2017-8054.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2018-11254"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2018-05-18T19:29:00Z",
    "severity": "MODERATE"
  },
  "details": "An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file, a related issue to CVE-2017-8054.",
  "id": "GHSA-397j-7mpf-rm74",
  "modified": "2022-05-13T01:49:10Z",
  "published": "2022-05-13T01:49:10Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-11254"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1576174"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-39FP-MQMM-GXJ6

Vulnerability from github – Published: 2024-03-29 16:36 – Updated: 2025-05-07 18:49
VLAI
Summary
CodeIgniter4 DoS Vulnerability
Details

Impact

A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server.

Patches

Upgrade to v4.4.7 or later. See upgrading guide.

Workarounds

  • Disabling Auto Routing prevents a known attack vector in the framework.
  • Do not pass invalid values to the lang() function or Language class.

References

  • https://codeigniter4.github.io/userguide/outgoing/localization.html#language-localization
  • https://codeigniter4.github.io/userguide/general/common_functions.html#lang
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Packagist",
        "name": "codeigniter4/framework"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.4.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-29904"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674",
      "CWE-835"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-03-29T16:36:38Z",
    "nvd_published_at": "2024-03-29T16:15:08Z",
    "severity": "HIGH"
  },
  "details": "### Impact\nA vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server.\n\n### Patches\nUpgrade to v4.4.7 or later. See [upgrading guide](https://codeigniter4.github.io/userguide/installation/upgrade_447.html).\n\n### Workarounds\n- Disabling Auto Routing prevents a known attack vector in the framework.\n- Do not pass invalid values to the `lang()` function or `Language` class.\n\n### References\n- https://codeigniter4.github.io/userguide/outgoing/localization.html#language-localization\n- https://codeigniter4.github.io/userguide/general/common_functions.html#lang",
  "id": "GHSA-39fp-mqmm-gxj6",
  "modified": "2025-05-07T18:49:41Z",
  "published": "2024-03-29T16:36:38Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-39fp-mqmm-gxj6"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29904"
    },
    {
      "type": "WEB",
      "url": "https://github.com/codeigniter4/CodeIgniter4/commit/fa851acbae7ae4c5a97f8f38ae87aa0822a334c0"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/codeigniter4/CodeIgniter4"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "CodeIgniter4 DoS Vulnerability"
}

GHSA-39VW-QP34-RMWF

Vulnerability from github – Published: 2021-08-25 21:00 – Updated: 2023-06-13 21:03
VLAI
Summary
Uncontrolled recursion leads to abort in deserialization
Details

Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "crates.io",
        "name": "serde_yaml"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.6.0-rc1"
            },
            {
              "fixed": "0.8.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2021-08-06T17:45:03Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "Affected versions of this crate did not properly check for recursion while deserializing aliases. This allows an attacker to make a YAML file with an alias referring to itself causing an abort. The flaw was corrected by checking the recursion depth.\n",
  "id": "GHSA-39vw-qp34-rmwf",
  "modified": "2023-06-13T21:03:35Z",
  "published": "2021-08-25T21:00:18Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/dtolnay/serde-yaml/pull/105"
    },
    {
      "type": "WEB",
      "url": "https://github.com/dtolnay/serde-yaml/commit/b93aff6e904cffbbfd1f421b82f6dcc5ca19a4fd"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/dtolnay/serde-yaml"
    },
    {
      "type": "WEB",
      "url": "https://rustsec.org/advisories/RUSTSEC-2018-0005.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [],
  "summary": "Uncontrolled recursion leads to abort in deserialization"
}

GHSA-3C37-WWVX-H642

Vulnerability from github – Published: 2026-03-23 20:23 – Updated: 2026-03-25 20:38
VLAI
Summary
cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads
Details

Summary

  • The cbor2 library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding deeply nested CBOR structures.
  • This vulnerability affects both the pure Python implementation and the C extension (_cbor2). The C extension correctly uses Python's C-API for recursion protection (Py_EnterRecursiveCall), but this mechanism is designed to prevent a stack overflow by raising a RecursionError. In some environments, this exception is not caught, thus causing the service process to terminate.
  • While the library handles moderate nesting, it lacks a configurable, data-driven depth limit independent of Python's global recursion setting. An attacker can supply a crafted CBOR payload containing thousands of nested arrays (e.g., 0x81). When cbor2.loads() attempts to parse this, it hits the interpreter's recursion limit, causing the call to raise a RecursionError.
  • By sending a stream of small (<100KB) malicious packets, an attacker can repeatedly crash worker processes faster than they can be restarted, resulting in a complete and sustained Denial of Service.

Details

  • The vulnerability stems from the recursive design of the CBORDecoder class, specifically how it decodes nested container types like Arrays and Maps.
  • Inside decode_array (and similarly decode_map), the decoder iterates through the number of elements specified in the CBOR header. For each element, it calls self.decode() again to parse the nested item. This recursive call lacks a depth-tracking mechanism.
  • Vulnerable Code Locations:
  • cbor2/decoder.py (Pure Python implementation)
  • source/decoder.c (C extension implementation)
  • Execution Flow:
  • The cbor2.loads() function initializes a CBORDecoder and calls its decode() method.
  • The decode() method reads the initial byte and dispatches control to a specific handler based on the major type. For an Array (Major Type 4), it calls decode_array.
  • decode_array loops and calls self.decode() for each item, leading to deep recursion when parsing a payload like [...[...[1]...]...].

PoC

import cbor2

DEPTH = 1000

payload = b'\x81' * DEPTH + b'\x01'
print(f"[*] Payload size: {len(payload) / 1024:.2f} KB")
print("[*] Triggering decoder...")

try:
    cbor2.loads(payload)
    print("[+] Parsed successfully (Not Vulnerable)")
except RecursionError:
    print("\n[!] VULNERABLE: RecursionError triggered!")
except Exception as e:
    print(f"\n[-] Unexpected Error: {type(e).__name__}: {e}")

Impact

  • Scope: This vulnerability affects any application using cbor2 to parse untrusted data. Common use cases include IoT data processing, WebAuthn (FIDO2) authentication flows, and inter-service communication over COSE (CBOR Object Signing and Encryption).
  • Attack Vector: A remote, unauthenticated attacker can achieve a full Denial of Service with a highly efficient, low-bandwidth attack. A payload under 100KB is sufficient to reliably terminate a Python worker process.

Credit

This issue was discovered by Kevin Tu of TMIR at ByteDance. The patch was developed by @agronholm.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 5.8.0"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "cbor2"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.9.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-26209"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-23T20:23:57Z",
    "nvd_published_at": "2026-03-23T19:16:39Z",
    "severity": "HIGH"
  },
  "details": "### Summary\n\n- The `cbor2` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding deeply nested CBOR structures.\n- This vulnerability affects both the pure Python implementation and the C extension (`_cbor2`). The C extension correctly uses Python\u0027s C-API for recursion protection (`Py_EnterRecursiveCall`), but this mechanism is designed to prevent a stack overflow by raising a `RecursionError`. In some environments, this exception is not caught, thus causing the service process to terminate.\n- While the library handles moderate nesting, it lacks a configurable, data-driven depth limit independent of Python\u0027s global recursion setting. An attacker can supply a crafted CBOR payload containing thousands of nested arrays (e.g., `0x81`). When `cbor2.loads()` attempts to parse this, it hits the interpreter\u0027s recursion limit, causing the call to raise a `RecursionError`.\n- By sending a stream of small (\u003c100KB) malicious packets, an attacker can repeatedly crash worker processes faster than they can be restarted, resulting in a complete and sustained Denial of Service.\n\n### Details\n\n- The vulnerability stems from the recursive design of the `CBORDecoder` class, specifically how it decodes nested container types like Arrays and Maps.\n- Inside `decode_array` (and similarly `decode_map`), the decoder iterates through the number of elements specified in the CBOR header. For each element, it calls `self.decode()` again to parse the nested item. This recursive call lacks a depth-tracking mechanism.\n- Vulnerable Code Locations:\n  - `cbor2/decoder.py` (Pure Python implementation)\n  - `source/decoder.c` (C extension implementation)\n- Execution Flow:\n  1. The `cbor2.loads()` function initializes a `CBORDecoder` and calls its `decode()` method.\n  2. The `decode()` method reads the initial byte and dispatches control to a specific handler based on the major type. For an Array (Major Type 4), it calls `decode_array`.\n  3. `decode_array` loops and calls `self.decode()` for each item, leading to deep recursion when parsing a payload like `[...[...[1]...]...]`.\n\n### PoC\n\n```\nimport cbor2\n\nDEPTH = 1000\n\npayload = b\u0027\\x81\u0027 * DEPTH + b\u0027\\x01\u0027\nprint(f\"[*] Payload size: {len(payload) / 1024:.2f} KB\")\nprint(\"[*] Triggering decoder...\")\n\ntry:\n    cbor2.loads(payload)\n    print(\"[+] Parsed successfully (Not Vulnerable)\")\nexcept RecursionError:\n    print(\"\\n[!] VULNERABLE: RecursionError triggered!\")\nexcept Exception as e:\n    print(f\"\\n[-] Unexpected Error: {type(e).__name__}: {e}\")\n```\n\n### Impact\n\n- Scope: This vulnerability affects any application using `cbor2` to parse untrusted data. Common use cases include IoT data processing, WebAuthn (FIDO2) authentication flows, and inter-service communication over COSE (CBOR Object Signing and Encryption).\n- Attack Vector: A remote, unauthenticated attacker can achieve a full Denial of Service with a highly efficient, low-bandwidth attack. A payload under 100KB is sufficient to reliably terminate a Python worker process.\n\n### Credit\n\nThis issue was discovered by Kevin Tu of TMIR at ByteDance. The patch was developed by @agronholm.",
  "id": "GHSA-3c37-wwvx-h642",
  "modified": "2026-03-25T20:38:41Z",
  "published": "2026-03-23T20:23:57Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/agronholm/cbor2/security/advisories/GHSA-3c37-wwvx-h642"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26209"
    },
    {
      "type": "WEB",
      "url": "https://github.com/agronholm/cbor2/pull/275"
    },
    {
      "type": "WEB",
      "url": "https://github.com/agronholm/cbor2/commit/e61a5f365ba610d5907a0ae1bc72769bba34294b"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/agronholm/cbor2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/agronholm/cbor2/releases/tag/5.9.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads"
}

GHSA-3C6W-J9XM-8H2H

Vulnerability from github – Published: 2026-10-08 17:51 – Updated: 2026-10-08 17:51
VLAI
Summary
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
Details

Summary

The JSON response body processor parses response bodies with no recursion limit. ProcessResponse calls readJSON(ss, ignoreJSONRecursionLimit), and that constant is -1. The guard in readItems only fires on == 0, so counting down from -1 (-2, -3, ...) never reaches it. The guard is effectively dead on the response path. The request path is fine: ProcessRequest passes the configured limit (default 1024). There is no equivalent directive or default for responses.

Parsing a deeply nested JSON response is CPU-bound and its cost grows quadratically with nesting depth. A 512 KiB response (the default ResponseBodyLimit) holds about 87,000 nesting levels and takes ~12 s to process, keeping one core busy the whole time.

Root cause

internal/bodyprocessors/json.go

const ignoreJSONRecursionLimit = -1                     // line 51

func (js *jsonBodyProcessor) ProcessResponse(reader io.Reader, v ..., _ plugintypes.BodyProcessorOptions) error {
    ...
    data, err := readJSON(ss, ignoreJSONRecursionLimit) // line 62, passes -1
}

func (js *jsonBodyProcessor) ProcessRequest(...) error {
    ...
    data, err := readJSON(ss, bpo.RequestBodyRecursionLimit) // line 32, default 1024
}

The guard and the decrement:

func readItems(json gjson.Result, objKey []byte, maxRecursion int, res map[string]string) error {
    if maxRecursion == 0 {                              // line 106
        return errors.New("max recursion reached while reading json object")
    }
    ...
    iterationError = readItems(value, objKey, maxRecursion-1, res) // line 126

Note that ProcessResponse discards BodyProcessorOptions (the parameter is _), so even a caller that wanted to set a limit on responses has no way to.

Why the cost is quadratic

Every nesting level re-parses the remaining nested document through gjson.ForEach, so total work is O(n²) in the depth. Numbers below were measured on an Intel Core Ultra 7 255H, Go 1.22.2, gjson v1.18.0, at commit db9850b2 (v3.7.0-55):

depth   bytes    ProcessResponse time
5000    30004    30 ms
10000   60004    119 ms
20000   120004   456 ms
40000   240004   2.18 s
87381   524290   12.09 s

Log-log slope between adjacent rows lands between 1.93 and 2.26 (2.09 across the full range), which matches quadratic. Roughly 87,000 levels is the most that fits inside the default 512 KiB ResponseBodyLimit.

PoC

Save as internal/bodyprocessors/poc_json_test.go, then:

go test -v -timeout 120s -run TestPoCJSONResponse ./internal/bodyprocessors/...
package bodyprocessors_test

import (
      "strings"
      "testing"
      "time"

      "github.com/corazawaf/coraza/v3/experimental/plugins/plugintypes"
      "github.com/corazawaf/coraza/v3/internal/bodyprocessors"
      "github.com/corazawaf/coraza/v3/internal/corazawaf"
)

func nestedJSON(depth int) string {
      var sb strings.Builder
      sb.Grow(depth*6 + 4)
      for i := 0; i < depth; i++ {
              sb.WriteString(`{"a":`)
      }
      sb.WriteString("null")
      for i := 0; i < depth; i++ {
              sb.WriteByte('}')
      }
      return sb.String()
}

func TestPoCJSONResponse(t *testing.T) {
      proc, _ := bodyprocessors.GetBodyProcessor("json")

      // Request path is bounded, response path is not.
      body := nestedJSON(5000)
      v := corazawaf.NewTransactionVariables()
      errReq := proc.ProcessRequest(strings.NewReader(body), v,
              plugintypes.BodyProcessorOptions{RequestBodyRecursionLimit: 1024})
      errRes := proc.ProcessResponse(strings.NewReader(body), v,
              plugintypes.BodyProcessorOptions{})
      t.Logf("depth=5000 ProcessRequest  err=%v", errReq)
      t.Logf("depth=5000 ProcessResponse err=%v", errRes)

      // Quadratic scaling on the response path.
      for _, depth := range []int{5000, 10000, 20000, 40000, 87381} {
              b := nestedJSON(depth)
              vv := corazawaf.NewTransactionVariables()
              start := time.Now()
              proc.ProcessResponse(strings.NewReader(b), vv,
                      plugintypes.BodyProcessorOptions{})
              t.Logf("depth=%-6d bytes=%-7d time=%v", depth, len(b), time.Since(start))
      }
}

Output on the reference machine:

depth=5000 ProcessRequest  err=max recursion reached while reading json object
depth=5000 ProcessResponse err=<nil>
depth=5000   bytes=30004   time=30.3ms
depth=10000  bytes=60004   time=119.3ms
depth=20000  bytes=120004  time=456.1ms
depth=40000  bytes=240004  time=2.185s
depth=87381  bytes=524290  time=12.085s

Impact

This needs ResponseBodyAccess turned on and a backend that returns JSON (application/json). Reflection endpoints, download APIs that serve user-supplied content, and JSON error responses that echo back user input are all plausible ways to route a nested body back through the WAF.

The work happens in a single goroutine and is CPU-bound: the body is already in memory, so there is no I/O during the parse. Each such request holds one core for its entire run, about 12 s per 512 KiB body at the default limit. N concurrent requests take N cores. The request path has enforced a recursion limit since v3.3.3; responses never have.

Suggested fix

Bound ProcessResponse the same way the request path is bounded: add a ResponseBodyRecursionLimit directive, or just pass RequestBodyRecursionLimit instead of -1.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/corazawaf/coraza/v3"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0"
            },
            {
              "fixed": "3.8.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T17:51:42Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "### Summary\n\nThe JSON response body processor parses response bodies with no recursion\nlimit. `ProcessResponse` calls `readJSON(ss, ignoreJSONRecursionLimit)`, and\nthat constant is `-1`. The guard in `readItems` only fires on `== 0`, so\ncounting down from `-1` (-2, -3, ...) never reaches it. The guard is effectively\ndead on the response path. The request path is fine: `ProcessRequest` passes the\nconfigured limit (default 1024). There is no equivalent directive or default for\nresponses.\n\nParsing a deeply nested JSON response is CPU-bound and its cost grows\nquadratically with nesting depth. A 512 KiB response (the default\n`ResponseBodyLimit`) holds about 87,000 nesting levels and takes ~12 s to\nprocess, keeping one core busy the whole time.\n\n### Root cause\n\n`internal/bodyprocessors/json.go`\n\n```go\nconst ignoreJSONRecursionLimit = -1                     // line 51\n\nfunc (js *jsonBodyProcessor) ProcessResponse(reader io.Reader, v ..., _ plugintypes.BodyProcessorOptions) error {\n    ...\n    data, err := readJSON(ss, ignoreJSONRecursionLimit) // line 62, passes -1\n}\n\nfunc (js *jsonBodyProcessor) ProcessRequest(...) error {\n    ...\n    data, err := readJSON(ss, bpo.RequestBodyRecursionLimit) // line 32, default 1024\n}\n```\n\nThe guard and the decrement:\n\n```go\nfunc readItems(json gjson.Result, objKey []byte, maxRecursion int, res map[string]string) error {\n    if maxRecursion == 0 {                              // line 106\n        return errors.New(\"max recursion reached while reading json object\")\n    }\n    ...\n    iterationError = readItems(value, objKey, maxRecursion-1, res) // line 126\n```\n\nNote that `ProcessResponse` discards `BodyProcessorOptions` (the parameter is\n`_`), so even a caller that wanted to set a limit on responses has no way to.\n\n### Why the cost is quadratic\n\nEvery nesting level re-parses the remaining nested document through\n`gjson.ForEach`, so total work is O(n\u00b2) in the depth. Numbers below were measured\non an Intel Core Ultra 7 255H, Go 1.22.2, gjson v1.18.0, at commit db9850b2\n(v3.7.0-55):\n\n```\ndepth   bytes    ProcessResponse time\n5000    30004    30 ms\n10000   60004    119 ms\n20000   120004   456 ms\n40000   240004   2.18 s\n87381   524290   12.09 s\n```\n\nLog-log slope between adjacent rows lands between 1.93 and 2.26 (2.09 across the\nfull range), which matches quadratic. Roughly 87,000 levels is the most that\nfits inside the default 512 KiB `ResponseBodyLimit`.\n\n### PoC\n\nSave as `internal/bodyprocessors/poc_json_test.go`, then:\n\n```\ngo test -v -timeout 120s -run TestPoCJSONResponse ./internal/bodyprocessors/...\n```\n\n```go\npackage bodyprocessors_test\n\nimport (\n      \"strings\"\n      \"testing\"\n      \"time\"\n\n      \"github.com/corazawaf/coraza/v3/experimental/plugins/plugintypes\"\n      \"github.com/corazawaf/coraza/v3/internal/bodyprocessors\"\n      \"github.com/corazawaf/coraza/v3/internal/corazawaf\"\n)\n\nfunc nestedJSON(depth int) string {\n      var sb strings.Builder\n      sb.Grow(depth*6 + 4)\n      for i := 0; i \u003c depth; i++ {\n              sb.WriteString(`{\"a\":`)\n      }\n      sb.WriteString(\"null\")\n      for i := 0; i \u003c depth; i++ {\n              sb.WriteByte(\u0027}\u0027)\n      }\n      return sb.String()\n}\n\nfunc TestPoCJSONResponse(t *testing.T) {\n      proc, _ := bodyprocessors.GetBodyProcessor(\"json\")\n\n      // Request path is bounded, response path is not.\n      body := nestedJSON(5000)\n      v := corazawaf.NewTransactionVariables()\n      errReq := proc.ProcessRequest(strings.NewReader(body), v,\n              plugintypes.BodyProcessorOptions{RequestBodyRecursionLimit: 1024})\n      errRes := proc.ProcessResponse(strings.NewReader(body), v,\n              plugintypes.BodyProcessorOptions{})\n      t.Logf(\"depth=5000 ProcessRequest  err=%v\", errReq)\n      t.Logf(\"depth=5000 ProcessResponse err=%v\", errRes)\n\n      // Quadratic scaling on the response path.\n      for _, depth := range []int{5000, 10000, 20000, 40000, 87381} {\n              b := nestedJSON(depth)\n              vv := corazawaf.NewTransactionVariables()\n              start := time.Now()\n              proc.ProcessResponse(strings.NewReader(b), vv,\n                      plugintypes.BodyProcessorOptions{})\n              t.Logf(\"depth=%-6d bytes=%-7d time=%v\", depth, len(b), time.Since(start))\n      }\n}\n```\n\nOutput on the reference machine:\n\n```\ndepth=5000 ProcessRequest  err=max recursion reached while reading json object\ndepth=5000 ProcessResponse err=\u003cnil\u003e\ndepth=5000   bytes=30004   time=30.3ms\ndepth=10000  bytes=60004   time=119.3ms\ndepth=20000  bytes=120004  time=456.1ms\ndepth=40000  bytes=240004  time=2.185s\ndepth=87381  bytes=524290  time=12.085s\n```\n\n### Impact\n\nThis needs `ResponseBodyAccess` turned on and a backend that returns JSON\n(`application/json`). Reflection endpoints, download APIs that serve\nuser-supplied content, and JSON error responses that echo back user input are\nall plausible ways to route a nested body back through the WAF.\n\nThe work happens in a single goroutine and is CPU-bound: the body is already in\nmemory, so there is no I/O during the parse. Each such request holds one core\nfor its entire run, about 12 s per 512 KiB body at the default limit. N\nconcurrent requests take N cores. The request path has enforced a recursion\nlimit since v3.3.3; responses never have.\n\n### Suggested fix\n\nBound `ProcessResponse` the same way the request path is bounded: add a\n`ResponseBodyRecursionLimit` directive, or just pass `RequestBodyRecursionLimit`\ninstead of `-1`.",
  "id": "GHSA-3c6w-j9xm-8h2h",
  "modified": "2026-10-08T17:51:42Z",
  "published": "2026-10-08T17:51:42Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h"
    },
    {
      "type": "WEB",
      "url": "https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/corazawaf/coraza"
    },
    {
      "type": "WEB",
      "url": "https://github.com/corazawaf/coraza/releases/tag/v3.8.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion"
}

GHSA-3F92-Q4C5-7PPR

Vulnerability from github – Published: 2022-05-13 01:49 – Updated: 2022-05-13 01:49
VLAI
Details

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2018-11597"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2018-05-31T16:29:00Z",
    "severity": "MODERATE"
  },
  "details": "Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many \u0027{\u0027 characters in jsparse.c.",
  "id": "GHSA-3f92-q4c5-7ppr",
  "modified": "2022-05-13T01:49:18Z",
  "published": "2022-05-13T01:49:18Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-11597"
    },
    {
      "type": "WEB",
      "url": "https://github.com/espruino/Espruino/issues/1448"
    },
    {
      "type": "WEB",
      "url": "https://github.com/espruino/Espruino/commit/51380baf17241728b6d48cdb84140b931e3e3cc5"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3FFH-3H59-484G

Vulnerability from github – Published: 2022-05-24 17:07 – Updated: 2023-09-20 00:30
VLAI
Details

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2019-20395"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-01-22T22:15:00Z",
    "severity": "MODERATE"
  },
  "details": "A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.",
  "id": "GHSA-3ffh-3h59-484g",
  "modified": "2023-09-20T00:30:15Z",
  "published": "2022-05-24T17:07:08Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20395"
    },
    {
      "type": "WEB",
      "url": "https://github.com/CESNET/libyang/issues/724"
    },
    {
      "type": "WEB",
      "url": "https://github.com/CESNET/libyang/commit/4e610ccd87a2ba9413819777d508f71163fcc237"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1793924"
    },
    {
      "type": "WEB",
      "url": "https://github.com/CESNET/libyang/compare/v0.16-r3...v1.0-r1"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00019.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3FGQ-P3W2-7Q9W

Vulnerability from github – Published: 2022-09-20 00:00 – Updated: 2022-09-22 00:00
VLAI
Details

An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-28201"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-09-19T21:15:00Z",
    "severity": "MODERATE"
  },
  "details": "An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.",
  "id": "GHSA-3fgq-p3w2-7q9w",
  "modified": "2022-09-22T00:00:26Z",
  "published": "2022-09-20T00:00:21Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28201"
    },
    {
      "type": "WEB",
      "url": "https://blog.legoktm.com/2022/07/03/a-belated-writeup-of-cve-2022-28201-in-mediawiki.html"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00027.html"
    },
    {
      "type": "WEB",
      "url": "https://phabricator.wikimedia.org/T297571"
    },
    {
      "type": "WEB",
      "url": "https://www.debian.org/security/2022/dsa-5246"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3GF2-723M-W3FV

Vulnerability from github – Published: 2022-02-19 00:01 – Updated: 2025-05-30 21:30
VLAI
Details

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-25313"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400",
      "CWE-674"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-02-18T05:15:00Z",
    "severity": "MODERATE"
  },
  "details": "In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.",
  "id": "GHSA-3gf2-723m-w3fv",
  "modified": "2025-05-30T21:30:52Z",
  "published": "2022-02-19T00:01:37Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25313"
    },
    {
      "type": "WEB",
      "url": "https://github.com/libexpat/libexpat/pull/558"
    },
    {
      "type": "WEB",
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM"
    },
    {
      "type": "WEB",
      "url": "https://security.gentoo.org/glsa/202209-24"
    },
    {
      "type": "WEB",
      "url": "https://security.netapp.com/advisory/ntap-20220303-0008"
    },
    {
      "type": "WEB",
      "url": "https://www.debian.org/security/2022/dsa-5085"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2022/02/19/1"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-3HJH-JH2H-VRG6

Vulnerability from github – Published: 2024-06-06 21:30 – Updated: 2024-11-04 15:27
VLAI
Summary
Denial of service in langchain-community
Details

Denial of service in SitemapLoader Document Loader in the langchain-community package, affecting versions below 0.2.5. The parse_sitemap method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on this functionality.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "langchain-community"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.2.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "langchain"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.2.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-2965"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-400",
      "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-06-06T22:20:20Z",
    "nvd_published_at": "2024-06-06T19:15:55Z",
    "severity": "MODERATE"
  },
  "details": "Denial of service in `SitemapLoader` Document Loader in the `langchain-community` package, affecting versions below 0.2.5. The `parse_sitemap` method, responsible for parsing sitemaps and extracting URLs, lacks a mechanism to prevent infinite recursion when a sitemap URL refers to the current sitemap itself. This oversight allows for the possibility of an infinite loop, leading to a crash by exceeding the maximum recursion depth in Python. This vulnerability can be exploited to occupy server socket/port resources and crash the Python process, impacting the availability of services relying on this functionality.",
  "id": "GHSA-3hjh-jh2h-vrg6",
  "modified": "2024-11-04T15:27:57Z",
  "published": "2024-06-06T21:30:36Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2965"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langchain-ai/langchain/pull/22903"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langchain-ai/langchain/commit/73c42306745b0831aa6fe7fe4eeb70d2c2d87a82"
    },
    {
      "type": "WEB",
      "url": "https://github.com/langchain-ai/langchain/commit/9a877c7adbd06f90a2518152f65b562bd90487cc"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/langchain-ai/langchain"
    },
    {
      "type": "WEB",
      "url": "https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-118.yaml"
    },
    {
      "type": "WEB",
      "url": "https://huntr.com/bounties/90b0776d-9fa6-4841-aac4-09fde5918cae"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Denial of service in langchain-community"
}

Mitigation
Implementation

Ensure that an end condition will be reached under all logic conditions. The end condition may include checking against the depth of recursion and exiting with an error if the recursion goes too deep. The complexity of the end condition contributes to the effectiveness of this action.

Mitigation
Implementation

Increase the stack size.

CAPEC-230: Serialized Data with Nested Payloads

Applications often need to transform data in and out of a data format (e.g., XML and YAML) by using a parser. It may be possible for an adversary to inject data that may have an adverse effect on the parser when it is being processed. Many data format languages allow the definition of macro-like structures that can be used to simplify the creation of complex structures. By nesting these structures, causing the data to be repeatedly substituted, an adversary can cause the parser to consume more resources while processing, causing excessive memory consumption and CPU utilization.

CAPEC-231: Oversized Serialized Data Payloads

An adversary injects oversized serialized data payloads into a parser during data processing to produce adverse effects upon the parser such as exhausting system resources and arbitrary code execution.