Which is why it's reasonable to have configurable limits for both processing space and time in anything handling untrusted data.
Doing it all in your VM/runtime, so you can bail the computation with an exception, is more challenging.
Is forking a new process on each call to a recursive function practical?