目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-835 不可达退出条件的循环(无限循环) 类漏洞列表 334

CWE-835 不可达退出条件的循环(无限循环) 类弱点 334 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-835属于逻辑缺陷类漏洞,指程序包含无法到达退出条件的循环,导致无限执行。攻击者通常利用此缺陷发起拒绝服务攻击,通过触发无限循环耗尽服务器CPU资源或内存,使合法用户无法访问服务。开发者应避免此类问题,需确保循环变量在每次迭代中正确更新,并设置合理的边界检查或超时机制,保证循环最终能正常终止。

MITRE CWE 官方描述
CWE:CWE-835 具有不可达退出条件的循环('Infinite Loop') 英文:该产品包含一个迭代或循环,其退出条件无法被到达,即无限循环。
常见影响 (1)
Availability DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Amplification
An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.
代码示例 (2)
In the following code the method processMessagesFromServer attempts to establish a connection to a server and read and process messages from the server. The method uses a do/while loop to continue trying to establish the connection to the server when an attempt fails.
int processMessagesFromServer(char *hostaddr, int port) { ... int servsock; int connected; struct sockaddr_in servaddr; // create socket to connect to server servsock = socket( AF_INET, SOCK_STREAM, 0); memset( &servaddr, 0, sizeof(servaddr)); servaddr.sin_family = AF_INET; servaddr.sin_port = htons(port); servaddr.sin_addr.s_addr = inet_addr(hostaddr); do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep tr
Bad · C
int processMessagesFromServer(char *hostaddr, int port) { ... // initialize number of attempts counter int count = 0; do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // increment counter count++; // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep trying to establish connection to the server // up to a maximum number of attempts } while (connected < 0 && count < MAX_ATTEMPTS); // close socket and return success or failure ... }
Good · C
For this example, the method isReorderNeeded is part of a bookstore application that determines if a particular book needs to be reordered based on the current inventory count and the rate at which the book is being sold.
public boolean isReorderNeeded(String bookISBN, int rateSold) { boolean isReorder = false; int minimumCount = 10; int days = 0; // get inventory count for book int inventoryCount = inventory.getIventoryCount(bookISBN); // find number of days until inventory count reaches minimum while (inventoryCount > minimumCount) { inventoryCount = inventoryCount - rateSold; days++; } // if number of days within reorder timeframe // set reorder return boolean to true if (days > 0 && days < 5) { isReorder = true; } return isReorder; }
Bad · Java
public boolean isReorderNeeded(String bookISBN, int rateSold) { ... // validate rateSold variable if (rateSold < 1) { return isReorder; } ... }
Good · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-106164 Telerik文档处理XLS导入无限循环漏洞 — Telerik Document Processing Libraries 7.3 High 2026-10-07
CVE-2026-106568 ImageMagick 读取伪造XMP配置文件时无限循环漏洞 — ImageMagick 5.3 Medium 2026-10-07
CVE-2026-107168 M17n-lib count_utf_8_chars函数因畸形UTF-8导致无限循环 — Red Hat Enterprise Linux 10 6.2 Medium 2026-10-07
CVE-2026-106121 RabbitMQ JSON-RPC映射器截断输入导致拒绝服务漏洞 — rabbitmq-java-client 4.9 Medium 2026-10-06
CVE-2026-106116 ImageSharp BigTIFF IFD计数导致解码线程死循环漏洞 — ImageSharp 5.3 Medium 2026-10-06
CVE-2026-88252 SSSD 文件描述符耗尽时拒绝服务漏洞 — Red Hat Enterprise Linux 10 4.7 Medium 2026-10-06
CVE-2026-85476 Apache Thrift c_glib read_all 无限循环漏洞 — Apache Thrift 8.2 High 2026-10-02
CVE-2026-94654 Apache Thrift Python TNonblockingServer 文件描述符选择阻塞漏洞 — Apache Thrift 8.2 High 2026-10-02
CVE-2026-86535 Apache Thrift Node服务器JSON成员名导致事件循环阻塞漏洞 — Apache Thrift 8.7 High 2026-10-02
CVE-2026-63575 PKCS#12 密钥派生迭代计数负数漏洞 — bc-csharp 7.1 High 2026-10-02
CVE-2026-63570 Pkcs12Store.GetCertificateChain 循环依赖死循环漏洞 — bc-csharp 7.1 High 2026-10-02
CVE-2026-96780 figlet 宽度过小使用 whitespaceBreak 导致拒绝服务漏洞 — figlet.js 8.2 High 2026-10-01
CVE-2026-103492 JetBrains YouTrack 2026.2前PSD附件DoS漏洞 — YouTrack 6.5 Medium 2026-10-01
CVE-2026-102253 iperf3 3.22 拒绝服务漏洞 — iperf3 7.5 High 2026-09-29
CVE-2026-97688 urllib3 Chunked Deflate 无限循环漏洞 — urllib3 6.9 Medium 2026-09-29
CVE-2026-95386 Wireshark 无限循环漏洞 — Wireshark 5.5 Medium 2026-09-29
CVE-2026-96418 Wireshark 存在无限循环漏洞 — Wireshark 5.5 Medium 2026-09-29
CVE-2026-97362 HFS2 2.4.0 未认证拒绝服务漏洞 — hfs2 7.5 High 2026-09-24
CVE-2026-87082 Perl Net::IDN::Punycode 2.590前拒绝服务漏洞 - - 2026-09-22
CVE-2026-82560 Perl Pod::Text 6.1.1 前资源耗尽漏洞 - - 2026-09-19
CVE-2026-61633 NanoMQ UNSUBSCRIBE解码器无限循环导致远程拒绝服务 — nanomq 2.0 Low 2026-09-18
CVE-2026-84446 libheif 序列解码时序表初始化导致非终止循环 — libheif 7.5 High 2026-09-18
CVE-2026-93690 uri-js 4.4.1 远程拒绝服务漏洞 — uri-js 7.5 High 2026-09-18
CVE-2026-20154 Cisco Secure Firewall 日志拒绝服务漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 8.6 High 2026-09-16
CVE-2026-62949 AsyncSSH 最大包大小为0导致事件循环冻结漏洞 — asyncssh 6.5 Medium 2026-09-16
CVE-2026-84997 React 恶意 HTTP 分块请求致拒绝服务 — http 7.5 High 2026-09-16
CVE-2026-69210 http4s 输入验证错误漏洞 — http4s 7.5 High 2026-09-15
CVE-2026-91952 FreeRDP 资源管理错误漏洞 — FreeRDP 6.5 Medium 2026-09-15
CVE-2026-80489 Python 库 EUC_JISX0213 解码输入挂起漏洞 — glibc 5.9 Medium 2026-09-15
CVE-2026-77117 libiconv SHIFT_JIS 解码器挂起漏洞 — glibc 5.9 Medium 2026-09-15

CWE-835(不可达退出条件的循环(无限循环)) 是常见的弱点类别,本平台收录该类弱点关联的 334 条 CVE 漏洞。