Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-835 (不可达退出条件的循环(无限循环)) — Vulnerability Class 334

334 vulnerabilities classified as CWE-835 (不可达退出条件的循环(无限循环)). AI Chinese analysis included.

CWE-835 represents a logic error where a software loop lacks a reachable termination condition, resulting in an infinite execution cycle. This weakness typically manifests when developers fail to update loop variables correctly or rely on floating-point comparisons prone to precision errors. Attackers exploit this vulnerability to trigger Denial of Service (DoS) attacks by consuming excessive CPU resources, effectively freezing the application or system. To mitigate this risk, developers must ensure loop counters are properly incremented or decremented within the iteration body. Implementing strict boundary checks, avoiding direct equality comparisons with floating-point numbers, and utilizing static analysis tools can help detect unreachable exit conditions early. Additionally, incorporating timeout mechanisms or maximum iteration limits provides a safety net, ensuring that even if logic errors occur, the process terminates gracefully without exhausting system resources.

MITRE CWE Description
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Common Consequences (1)
Availability DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Amplification
An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.
Examples (2)
In the following code the method processMessagesFromServer attempts to establish a connection to a server and read and process messages from the server. The method uses a do/while loop to continue trying to establish the connection to the server when an attempt fails.
int processMessagesFromServer(char *hostaddr, int port) { ... int servsock; int connected; struct sockaddr_in servaddr; // create socket to connect to server servsock = socket( AF_INET, SOCK_STREAM, 0); memset( &servaddr, 0, sizeof(servaddr)); servaddr.sin_family = AF_INET; servaddr.sin_port = htons(port); servaddr.sin_addr.s_addr = inet_addr(hostaddr); do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep tr
Bad · C
int processMessagesFromServer(char *hostaddr, int port) { ... // initialize number of attempts counter int count = 0; do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // increment counter count++; // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep trying to establish connection to the server // up to a maximum number of attempts } while (connected < 0 && count < MAX_ATTEMPTS); // close socket and return success or failure ... }
Good · C
For this example, the method isReorderNeeded is part of a bookstore application that determines if a particular book needs to be reordered based on the current inventory count and the rate at which the book is being sold.
public boolean isReorderNeeded(String bookISBN, int rateSold) { boolean isReorder = false; int minimumCount = 10; int days = 0; // get inventory count for book int inventoryCount = inventory.getIventoryCount(bookISBN); // find number of days until inventory count reaches minimum while (inventoryCount > minimumCount) { inventoryCount = inventoryCount - rateSold; days++; } // if number of days within reorder timeframe // set reorder return boolean to true if (days > 0 && days < 5) { isReorder = true; } return isReorder; }
Bad · Java
public boolean isReorderNeeded(String bookISBN, int rateSold) { ... // validate rateSold variable if (rateSold < 1) { return isReorder; } ... }
Good · Java
CVE ID Title CVSS Severity Published
CVE-2026-15923 Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size — zephyr 4.6 Medium 2026-09-14
CVE-2023-37366 Google Pixel 安全漏洞 — Exynos 850 firmware 2.8 Low 2026-09-14
CVE-2026-78132 strongSwan 资源管理错误漏洞 — strongSwan 7.5 High 2026-09-11
CVE-2026-78129 strongSwan 资源管理错误漏洞 — strongSwan 5.9 Medium 2026-09-11
CVE-2026-89045 zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length — zstd-jni 4.0 Medium 2026-09-10
CVE-2026-88002 Open WebUI: Any authenticated user can hang the server via a cyclic chat message history — open-webui 6.5 Medium 2026-09-09
CVE-2026-88000 Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree — open-webui 6.5 Medium 2026-09-09
CVE-2026-87013 Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle — open-webui 4.3 Medium 2026-09-09
CVE-2026-6554 infinte loop in libpcap before 1.10.7 — libpcap 5.5 Medium 2026-09-05
CVE-2026-78543 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs — App Connect Enterprise 5.3 Medium 2026-09-04
CVE-2026-84309 pypdf: Possible infinite loop for TreeObject.insert_child — pypdf 6.9 Medium 2026-09-01
CVE-2026-82605 BareBones BBEdit Lasso Language Tokenizer infinite loop — BBEdit 4.3 Medium 2026-08-31
CVE-2026-82579 AshAi tool loop never terminates when all tool calls are filtered out, enabling denial of service — ash_ai 6.0 Medium 2026-08-31
CVE-2025-10903 Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab — GitLab 6.5 Medium 2026-08-26
CVE-2026-78250 bytebot-ai bytebot Agent Execution Workflow infinite loop — bytebot 4.3 Medium 2026-08-24
CVE-2026-45271 picotls has infinite recursion in the minicrypto ASN.1 decoder — picotls 5.5 Medium 2026-08-21
CVE-2026-61556 LiquidJS: An infinite loop vulnerability in `strip_html` filter — liquidjs 8.7 High 2026-08-19
CVE-2026-12629 PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service — zephyr 4.6 Medium 2026-08-17
CVE-2026-68762 JetBrains Ktor 资源管理错误漏洞 — Ktor 5.9 Medium 2026-08-17
CVE-2026-13002 Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing — Red Hat Enterprise Linux 10 4.4 Medium 2026-08-14
CVE-2026-17004 IBM i is Affected By Multiple Vulnerabilities in Host Servers — i 7.5 High 2026-08-13
CVE-2026-17229 IBM i is Affected By Multiple Vulnerabilities in Host Servers — i 7.5 High 2026-08-13
CVE-2026-12236 Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length — zephyr 6.5 Medium 2026-08-13
CVE-2026-19484 @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary — @fastify/busboy 7.5 High 2026-08-13
CVE-2026-18726 Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing — Red Hat Enterprise Linux 10 6.5 Medium 2026-08-12
CVE-2026-11932 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Security Verify Access 5.3 Medium 2026-08-12
CVE-2026-16931 IBM i is Affected By A Denial of Service Vulnerability [] — i 7.5 High 2026-08-12
CVE-2026-72712 Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet — Nmap 6.5 Medium 2026-08-11
CVE-2026-8798 Native entropy source retries the CPU entropy instructions without limit — BC-FJA 8.7 High 2026-08-08
CVE-2026-71436 Mermaid XY Charts are vulnerable to an infinite loop DoS — mermaid 5.3 Medium 2026-08-06

Vulnerabilities classified as CWE-835 (不可达退出条件的循环(无限循环)) represent 334 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.