Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-835 (不可达退出条件的循环(无限循环)) — Vulnerability Class 334

334 vulnerabilities classified as CWE-835 (不可达退出条件的循环(无限循环)). AI Chinese analysis included.

CWE-835 represents a logic error where a software loop lacks a reachable termination condition, resulting in an infinite execution cycle. This weakness typically manifests when developers fail to update loop variables correctly or rely on floating-point comparisons prone to precision errors. Attackers exploit this vulnerability to trigger Denial of Service (DoS) attacks by consuming excessive CPU resources, effectively freezing the application or system. To mitigate this risk, developers must ensure loop counters are properly incremented or decremented within the iteration body. Implementing strict boundary checks, avoiding direct equality comparisons with floating-point numbers, and utilizing static analysis tools can help detect unreachable exit conditions early. Additionally, incorporating timeout mechanisms or maximum iteration limits provides a safety net, ensuring that even if logic errors occur, the process terminates gracefully without exhausting system resources.

MITRE CWE Description
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Common Consequences (1)
Availability DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Amplification
An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.
Examples (2)
In the following code the method processMessagesFromServer attempts to establish a connection to a server and read and process messages from the server. The method uses a do/while loop to continue trying to establish the connection to the server when an attempt fails.
int processMessagesFromServer(char *hostaddr, int port) { ... int servsock; int connected; struct sockaddr_in servaddr; // create socket to connect to server servsock = socket( AF_INET, SOCK_STREAM, 0); memset( &servaddr, 0, sizeof(servaddr)); servaddr.sin_family = AF_INET; servaddr.sin_port = htons(port); servaddr.sin_addr.s_addr = inet_addr(hostaddr); do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep tr
Bad · C
int processMessagesFromServer(char *hostaddr, int port) { ... // initialize number of attempts counter int count = 0; do { // establish connection to server connected = connect(servsock, (struct sockaddr *)&servaddr, sizeof(servaddr)); // increment counter count++; // if connected then read and process messages from server if (connected > -1) { // read and process messages ... } // keep trying to establish connection to the server // up to a maximum number of attempts } while (connected < 0 && count < MAX_ATTEMPTS); // close socket and return success or failure ... }
Good · C
For this example, the method isReorderNeeded is part of a bookstore application that determines if a particular book needs to be reordered based on the current inventory count and the rate at which the book is being sold.
public boolean isReorderNeeded(String bookISBN, int rateSold) { boolean isReorder = false; int minimumCount = 10; int days = 0; // get inventory count for book int inventoryCount = inventory.getIventoryCount(bookISBN); // find number of days until inventory count reaches minimum while (inventoryCount > minimumCount) { inventoryCount = inventoryCount - rateSold; days++; } // if number of days within reorder timeframe // set reorder return boolean to true if (days > 0 && days < 5) { isReorder = true; } return isReorder; }
Bad · Java
public boolean isReorderNeeded(String bookISBN, int rateSold) { ... // validate rateSold variable if (rateSold < 1) { return isReorder; } ... }
Good · Java
CVE ID Title CVSS Severity Published
CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return — libkcapi 5.1 Medium 2026-08-05
CVE-2026-10686 Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers — zephyr 5.8 Medium 2026-07-31
CVE-2026-68499 re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS) — node-re2 6.2 Medium 2026-07-30
CVE-2026-59901 Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang — netty 8.7 High 2026-07-29
CVE-2026-67214 nanoid Infinite Loop via Negative Size in non-secure module — nanoid 5.9 Medium 2026-07-29
CVE-2026-67213 nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom — nanoid 5.9 Medium 2026-07-29
CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS) — zephyr 2.4 Low 2026-07-27
CVE-2026-66730 facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser — facil.io 7.5 High 2026-07-27
CVE-2026-43871 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit — Apache Thrift 8.7 High 2026-07-27
CVE-2026-64611 Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel() — Red Hat Enterprise Linux 10 7.5 High 2026-07-23
CVE-2026-64834 FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer — FFmpeg 7.5 High 2026-07-22
CVE-2026-16551 Denial-of-Service in OpenCanary's MongoDB module — OpenCanary - - 2026-07-22
CVE-2026-45820 101arrowz fflate 资源管理错误漏洞 — fflate - - 2026-07-22
CVE-2026-59849 Libssh: libssh: denial of service via automatic certificate authentication loop — Red Hat Enterprise Linux 10 3.1 Low 2026-07-21
CVE-2026-59843 Libssh: libssh: denial of service via zero advertised channel packet size — Red Hat Enterprise Linux 10 6.5 Medium 2026-07-21
CVE-2026-54538 xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER — xrdp 7.5 High 2026-07-20
CVE-2025-71397 SurrealDB before 2.2.2 CPU Exhaustion via nested FOR loops — surrealdb 7.1 High 2026-07-18
CVE-2026-45785 OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle — openmcdf 6.2 Medium 2026-07-17
CVE-2026-7771 IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service — Db2 5.5 Medium 2026-07-17
CVE-2026-46378 Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal — dasel 6.2 Medium 2026-07-16
CVE-2026-13401 XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes — XML::Bare - - 2026-07-16
CVE-2026-13397 HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes — HTML::Bare - - 2026-07-16
CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability — Microsoft .NET Framework 3.5 AND 4.7.2 7.5 High 2026-07-14
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability — Microsoft .NET Framework 3.5 AND 4.7.2 5.9 Medium 2026-07-14
CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability — Azure Active Directory 7.5 High 2026-07-14
CVE-2026-54119 Windows Active Directory Denial of Service Vulnerability — Windows 10 Version 1607 7.5 High 2026-07-14
CVE-2026-62642 Roundcube webmail 资源管理错误漏洞 — Webmail 4.3 Medium 2026-07-14
CVE-2026-59203 Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service — Pillow 5.3 Medium 2026-07-14
CVE-2026-55865 Python Liquid: Infinite loop when parsing malformed `{% case %}` tags — liquid - - 2026-07-09
CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch — patch - - 2026-07-09

Vulnerabilities classified as CWE-835 (不可达退出条件的循环(无限循环)) represent 334 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.