CVE-2025-29776 - CVE House
Back to Database
Status published High CVE-2025-29776

Azle calling `setTimer` causes infinite loop of timers

Vulnerability Description

Azle is a WebAssembly runtime for TypeScript and JavaScript on ICP. Calling `setTimer` in Azle versions `0.27.0`, `0.28.0`, and `0.29.0` causes an immediate infinite loop of timers to be executed on the canister, each timer attempting to clean up the global state of the previous timer. The infinite loop will occur with any valid invocation of `setTimer`. The problem has been fixed as of Azle version `0.30.0`. As a workaround, if a canister is caught in this infinite loop after calling `setTimer`, the canister can be upgraded and the timers will all be cleared, thus ending the loop.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29776

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

demergent-labs

View all reports →

Affected Software

azle
Vulnerable Versions:
>= 0.27.0, < 0.30.0

Timeline

Official Publish: March 14th, 2025
Last Modified: March 15th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)