# CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')

> As of 2026-10-05, CWE-835 (Infinite Loop) underlies 4 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 2 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-835?

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

CWE-835 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Not Technology-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/835.html) (CWE-835 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Availability** — DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Amplification. An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.

_Source: MITRE CWE, common consequences._

## How CWE-835 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-835, published between 2026-06-18 and 2026-09-09. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 medium. The highest EPSS score in the set is 0.3% (CVE-2026-88002), the modelled probability of exploitation in the next 30 days. 2 tracked threats reference CWE-835 directly or through a CVE it covers; the most recent is “Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200)” (2026-07-11). Affected products concentrate in open-webui (2), The Tcpdump Group (1), mcdope (1).

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-835, CISA KEV first, then by CVSS score.

- [CVE-2026-88000](https://intel.threadlinqs.com/cve/CVE-2026-88000) — CVSS 6.5 medium · EPSS 0.3% · published 2026-09-09
- [CVE-2026-88002](https://intel.threadlinqs.com/cve/CVE-2026-88002) — CVSS 6.5 medium · EPSS 0.3% · published 2026-09-09
- [CVE-2026-6554](https://intel.threadlinqs.com/cve/CVE-2026-6554) — CVSS 5.5 medium · EPSS 0.0% · published 2026-09-05
- [CVE-2026-48986](https://intel.threadlinqs.com/cve/CVE-2026-48986) — CVSS 4.7 medium · published 2026-06-18

## Affected vendors

- [open-webui](https://intel.threadlinqs.com/vendors/open-webui) — 2 CVEs
- **The Tcpdump Group** — 1 CVE
- **mcdope** — 1 CVE

## Threat activity

2 tracked threats cite CWE-835:

- [Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200)](https://intel.threadlinqs.com/threat/TL-2026-1226) — CRITICAL · 2026-07-11
- [BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)](https://intel.threadlinqs.com/threat/TL-2026-0599) — HIGH · 2026-05-27

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-834](https://cwe.mitre.org/data/definitions/834.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-835
Source definition: https://cwe.mitre.org/data/definitions/835.html
Detection rules and IOCs for threats exploiting CWE-835 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
