Threadlinqs IntelligenceStart free

Weakness · BaseCWE-908

CWE-908: Use of Uninitialized Resource

Likelihood of exploit: MediumKEV-linkedBase

As of 2026-10-05, CWE-908 (Use of Uninitialized Resource) underlies 14 CVEs tracked by Threadlinqs, 3 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 19 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
14Mapped to CWE-908
CISA KEV
3Exploited in the wild
Critical
0CVSS v3 critical CVEs
Threats
19Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-908?

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

CWE-908 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Not Language-Specific.

Source: MITRE CWE (CWE-908 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality — Read Memory, Read Application Data. When reusing a resource such as memory or a program variable, the original contents of that resource may not be cleared before it is sent to an untrusted party.
  • Availability — DoS: Crash, Exit, or Restart. The uninitialized resource may contain values that cause program flow to change in ways that the programmer did not intend.

Source: MITRE CWE, common consequences.

How CWE-908 is exploited in the wild

Threadlinqs maps 14 CVEs to CWE-908, published between 2024-11-19 and 2026-09-29. 3 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 4 high, 9 medium, 1 low. The highest EPSS score in the set is 62.2% (CVE-2025-5777), the modelled probability of exploitation in the next 30 days. 19 tracked threats reference CWE-908 directly or through a CVE it covers; the most recent is “Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)” (2026-09-30). Affected products concentrate in Google (5), Microsoft (5), Citrix (1), among 6 vendors in total.

Vulnerabilities (CVEs)

All 14 CVEs mapped to CWE-908, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

19 tracked threats cite CWE-908:

Mitigations

  • Implementation: Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all required steps.
  • Implementation: Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.
  • Implementation: Avoid race conditions (CWE-362) during initialization routines.
  • Build and Compilation: Run or compile the product with settings that generate warnings about uninitialized variables or data.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.