CVE-2026-47309: CWE-674 Uncontrolled Recursion in Samsung Open Source Escargot
CVE-2026-47309 is an uncontrolled recursion vulnerability in Samsung Open Source Escargot that allows oversized serialized data payloads. This flaw can cause a denial of service by exhausting system resources due to recursive processing. The vulnerability affects a specific Escargot version identified by commit 590345cc6258317c5da850d846ce6baaf2afc2d3. There is no official patch or remediation level provided at this time. The CVSS score is 5.5, indicating a medium severity impact focused on availability. No known exploits are reported in the wild, and the product is not a cloud service. No geographic targeting is indicated.
AI Analysis
Technical Summary
The vulnerability CVE-2026-47309 in Samsung Open Source Escargot is classified as CWE-674 (Uncontrolled Recursion). It arises when oversized serialized data payloads are processed without proper recursion control, potentially leading to resource exhaustion and denial of service. The affected version is identified by a specific commit hash. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) reflects that the attack requires local access with low complexity, no privileges, and user interaction, impacting availability only. There is no vendor advisory or patch available, and no exploits have been observed in the wild.
Potential Impact
The primary impact is denial of service due to uncontrolled recursion triggered by oversized serialized data payloads. This can cause the affected system or application to become unresponsive or crash. There is no confidentiality or integrity impact reported. The medium CVSS score reflects the limited attack vector (local) and requirement for user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround is currently available, users should limit exposure by restricting local access to the affected Escargot version and avoid processing untrusted serialized data payloads. Monitor vendor channels for updates.
CVE-2026-47309: CWE-674 Uncontrolled Recursion in Samsung Open Source Escargot
Description
CVE-2026-47309 is an uncontrolled recursion vulnerability in Samsung Open Source Escargot that allows oversized serialized data payloads. This flaw can cause a denial of service by exhausting system resources due to recursive processing. The vulnerability affects a specific Escargot version identified by commit 590345cc6258317c5da850d846ce6baaf2afc2d3. There is no official patch or remediation level provided at this time. The CVSS score is 5.5, indicating a medium severity impact focused on availability. No known exploits are reported in the wild, and the product is not a cloud service. No geographic targeting is indicated.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-47309 in Samsung Open Source Escargot is classified as CWE-674 (Uncontrolled Recursion). It arises when oversized serialized data payloads are processed without proper recursion control, potentially leading to resource exhaustion and denial of service. The affected version is identified by a specific commit hash. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) reflects that the attack requires local access with low complexity, no privileges, and user interaction, impacting availability only. There is no vendor advisory or patch available, and no exploits have been observed in the wild.
Potential Impact
The primary impact is denial of service due to uncontrolled recursion triggered by oversized serialized data payloads. This can cause the affected system or application to become unresponsive or crash. There is no confidentiality or integrity impact reported. The medium CVSS score reflects the limited attack vector (local) and requirement for user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround is currently available, users should limit exposure by restricting local access to the affected Escargot version and avoid processing untrusted serialized data payloads. Monitor vendor channels for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- samsung.tv_appliance
- Date Reserved
- 2026-05-19T02:40:40.159Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a0c017aec166c07b0739c13
Added to database: 05/19/2026, 06:21:46 UTC
Last enriched: 05/26/2026, 08:27:02 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.