CVE-2020-13935
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.
CVSS
7.5
Alto
EPSS
86.6%
p100
KEV
—
Exploit Today
30
0-100
Publicado: 14 jul 2020 · Última mod.: 25 ago 2026 · CWE-835
86.6%EPSS · 30 días86.6%
2026-08-022026-08-31
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html
- kc.mcafee.comhttps://kc.mcafee.com/corporate/index?page=content&id=SB10332
- lists.apache.orghttps://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2020/07/msg00017.html
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20200724-0003/
- usn.ubuntu.comhttps://usn.ubuntu.com/4448-1/
- usn.ubuntu.comhttps://usn.ubuntu.com/4596-1/
- www.debian.orghttps://www.debian.org/security/2020/dsa-4727
- www.oracle.comhttps://www.oracle.com//security-alerts/cpujul2021.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpuApr2021.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpuapr2022.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpujan2021.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpujan2022.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpuoct2020.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpuoct2021.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html
- kc.mcafee.comhttps://kc.mcafee.com/corporate/index?page=content&id=SB10332
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-826054.3 MED25.5%
——8A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.14hCVE-2026-82579—18.6%
——6Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests.
AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a result in history, is dropped. With an empty list the loop appended nothing and recursed with a byte-identical message list, so the conversation never advanced and the same request was re-sent every iteration. Under the supported max_iterations: :infinity this never terminated; otherwise it exhausted the full budget. Prompt-injected content can make the model re-emit a spent tool_call_id. The fix treats an empty post-filter list as terminal.
This issue affects ash_ai: from 0.6.0 before 1.0.0.15hCVE-2026-478635.9 MED12.7%
——4In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 - 3.8.6
Reactor Core 3.7.19 and earlier3dCVE-2025-109036.5 MED35.2%
——11GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning feature.3dCVE-2026-555886.5 MED22.3%
——7ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.4dCVE-2026-782504.3 MED43.4%
——13A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to infinite loop. The attack may be performed from remote. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.4d