Cyber Posture

CWE · MITRE source

CWE-674Uncontrolled Recursion

Abstraction: Class · CVEs in our corpus: 388

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (2)AI

Control Title Family Why it addresses this CWE
CP-7Alternate Processing SiteCPSupports resumption at alternate site when uncontrolled recursion causes primary site failure or crash.
SC-5Denial-of-service ProtectionSCPrevents uncontrolled recursion that exhausts stack or CPU resources.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-426976.07.50.75542021-11-02
CVE-2021-451055.45.90.70432021-12-18
CVE-2019-132882.85.50.27512019-07-04
CVE-2020-121002.77.50.19612020-08-12
CVE-2007-34092.67.50.18032007-06-26
CVE-2017-85392.35.50.19182017-05-26
CVE-2017-85422.35.50.19182017-05-26
CVE-2018-07392.26.50.14442018-03-27
CVE-2024-43402.27.50.12402024-04-30
CVE-2020-122432.17.50.10762020-04-28
CVE-2018-10006182.09.80.00442018-07-09
CVE-2020-107042.07.50.08892020-05-06
CVE-2021-417522.09.80.00392022-04-05
CVE-2023-518032.09.80.00052024-04-01
CVE-2007-12851.97.50.06822007-03-06
CVE-2024-251111.98.60.03132024-03-06
CVE-2019-91431.88.80.00452019-02-25
CVE-2019-91441.88.80.01212019-02-25
CVE-2019-95431.88.80.00642019-03-01
CVE-2019-95451.88.80.00262019-03-01
CVE-2019-142351.87.50.04512019-08-02
CVE-2022-419661.88.20.02532022-12-28
CVE-2023-502691.88.60.01152023-12-14
CVE-2024-203111.88.60.00822024-03-27
CVE-2024-379731.88.80.01012024-07-09