CWE-674

CWE-674 · 6 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-674, highest CVSS first.

  1. HIGH 7.5CVE-2026-61483

    ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alterna

    lucy

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-68073

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the iss

    qpid broker-j

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-67590

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

    qpid protonj2

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-67552

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the i

    qpid proton-dotnet

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-66274

    A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the iss

    qpid proton-j

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.3CVE-2026-15830public PoC

    An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT),

    AI risk analysis on Exploit-DB.ai →