Threadlinqs IntelligenceStart free

Weakness · ClassCWE-674

CWE-674: Uncontrolled Recursion

Class

As of 2026-10-05, CWE-674 (Uncontrolled Recursion) underlies 9 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

CVEs
9Mapped to CWE-674
CISA KEV
0None listed yet
Critical
0CVSS v3 critical CVEs
Threats
10Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-674?

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

CWE-674 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

Source: MITRE CWE (CWE-674 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Availability — DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory). Resources including CPU, memory, and stack memory could be rapidly consumed or exhausted, eventually leading to an exit or crash.
  • Confidentiality — Read Application Data. In some cases, an application's interpreter might kill a process or thread that appears to be consuming too much resources, such as with PHP's memory_limit setting. When the interpreter kills the process/thread, it might report an error containing detailed information such as the application's installation path.

Source: MITRE CWE, common consequences.

How CWE-674 is exploited in the wild

Threadlinqs maps 9 CVEs to CWE-674, published between 2026-07-21 and 2026-09-28. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 8 high, 1 medium. The highest EPSS score in the set is 0.4% (CVE-2026-93435), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-674 directly or through a CVE it covers; the most recent is “Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40” (2026-09-25). Affected products concentrate in scriban (4), Elastic (1), EmilStenstrom (1), among 6 vendors in total.

Vulnerabilities (CVEs)

All 9 CVEs mapped to CWE-674, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

10 tracked threats cite CWE-674:

Mitigations

  • Implementation: Ensure an end condition will be reached under all logic conditions. The end condition may include testing against the depth of recursion and exiting with an error if the recursion goes too deep. The complexity of the end condition contributes to the effectiveness of this action.
  • Implementation: Increase the stack size.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.