Junglewise Threat Intelligence

CVE-2025-29776: Azle setTimer infinite loop denial of service

CVE-2025-29776 · Severity: medium · CVSS 4 · Published 2025-03-14

Vendors: npm.

Executive brief

Azle is a framework for building applications on the Internet Computer (ICP) blockchain platform. A vulnerability in versions 0.27.0 through 0.29.0 causes the `setTimer` function to trigger an uncontrolled infinite loop of timer executions that can exhaust system resources and render a deployed canister (smart contract) unresponsive. An attacker can trigger this remotely by invoking the vulnerable function without special privileges.

Technical details

The vulnerability is an infinite loop (CWE-835) in the `setTimer` function that occurs when called on Azle versions 0.27.0, 0.28.0, and 0.29.0. Each iteration of the loop attempts to clean up global state from the previous timer, causing cascading timer executions that quickly consume all available compute resources. The vulnerability is remotely exploitable over the network with no authentication or user interaction required—any valid invocation of `setTimer` triggers the infinite loop. The impact is denial of service to the affected canister, though it does not compromise confidentiality or integrity of other systems. The issue has been patched in Azle version 0.30.0; as a temporary workaround, affected canisters can be upgraded to clear all pending timers and end the loop.

Affected products

  • Demergent Labs Azle 0.27.0 to 0.29.0

Timeline

  • 2025-03-14: disclosed: Vulnerability disclosed via GitHub Security Advisory
  • 2025-03-14: patched: Fix released in Azle version 0.30.0

References