CVE Vulnerabilities

CVE-2025-43708

Uncontrolled Recursion

Published: Apr 17, 2025 | Modified: Sep 24, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference=../../../set/set[2] is used, aka an insecure deserialization issue.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
VisicutVisicut2.1 (including)2.1 (including)

Potential Mitigations

References