What is CWE-674?
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
CWE-674 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.
Source: MITRE CWE (CWE-674 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Availability — DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory). Resources including CPU, memory, and stack memory could be rapidly consumed or exhausted, eventually leading to an exit or crash.
- Confidentiality — Read Application Data. In some cases, an application's interpreter might kill a process or thread that appears to be consuming too much resources, such as with PHP's memory_limit setting. When the interpreter kills the process/thread, it might report an error containing detailed information such as the application's installation path.
Source: MITRE CWE, common consequences.
How CWE-674 is exploited in the wild
Threadlinqs maps 9 CVEs to CWE-674, published between 2026-07-21 and 2026-09-28. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 8 high, 1 medium. The highest EPSS score in the set is 0.4% (CVE-2026-93435), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-674 directly or through a CVE it covers; the most recent is “Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40” (2026-09-25). Affected products concentrate in scriban (4), Elastic (1), EmilStenstrom (1), among 6 vendors in total.
Vulnerabilities (CVEs)
All 9 CVEs mapped to CWE-674, CISA KEV first, then by CVSS score.
- CVE-2026-93435 — CVSS 7.5 high · EPSS 0.4% · published 2026-09-17
- CVE-2026-102281 — CVSS 7.5 high · EPSS 0.3% · published 2026-09-28
- CVE-2026-74795 — CVSS 7.5 high · EPSS 0.3% · published 2026-08-16
- CVE-2026-74792 — CVSS 7.5 high · EPSS 0.3% · published 2026-08-16
- CVE-2026-74783 — CVSS 7.5 high · EPSS 0.2% · published 2026-08-16
- CVE-2026-74794 — CVSS 7.5 high · EPSS 0.2% · published 2026-08-16
- CVE-2026-9769 — CVSS 7.5 high · EPSS 0.2% · published 2026-08-23
- CVE-2026-91765 — CVSS 7.5 high · published 2026-09-25
- CVE-2026-63144 — CVSS 6.5 medium · EPSS 0.2% · published 2026-07-21
Affected vendors
- scriban — 4 CVEs
- Elastic — 1 CVE
- EmilStenstrom — 1 CVE
- NodeRedis — 1 CVE
- PHP Group — 1 CVE
- nestjs — 1 CVE
Threat activity
10 tracked threats cite CWE-674:
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40MEDIUM
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access (CVE-2025-31718 + Unpatched MPU Privilege Escalation)HIGH
- 91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285CRITICAL
- Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel AccessCRITICAL
- Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel AccessHIGH
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and DjangoCRITICAL
- Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)HIGH
- Six AirDrop and Quick Share Proximity File-Transfer Vulnerabilities (Apple, Google, Samsung) — 'Protocol Prying' ResearchMEDIUM
- GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide MalwareMEDIUM
- CrackArmor — 9 Linux AppArmor Confused Deputy Vulnerabilities Enable Root Privilege Escalation and Container EscapeHIGH
Mitigations
- Implementation: Ensure an end condition will be reached under all logic conditions. The end condition may include testing against the depth of recursion and exiting with an error if the recursion goes too deep. The complexity of the end condition contributes to the effectiveness of this action.
- Implementation: Increase the stack size.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.