PatchSiren cyber security CVE debrief
CVE-2026-47309 Samsung Open Source CVE debrief
CVE-2026-47309 documents an uncontrolled recursion vulnerability in Samsung's Escargot JavaScript engine, specifically affecting commit 590345cc6258317c5da850d846ce6baaf2afc2d3. The flaw enables oversized serialized data payloads to trigger excessive recursion, resulting in denial of service through stack exhaustion. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) indicates a local attack vector requiring user interaction but no privileges, with high availability impact. Samsung's PSIRT has assigned CWE-674 (Uncontrolled Recursion) as the weakness classification. The vulnerability was disclosed on May 19, 2026, with NVD analysis status currently marked as 'Undergoing Analysis'. A pull request (#1565) has been submitted to the Escargot repository addressing this issue.
- Vendor
- Samsung Open Source
- Product
- Escargot
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-07-24
Who should care
Organizations deploying Escargot-based applications, embedded systems using Samsung's JavaScript engine, and developers maintaining forks or custom builds of Escargot should prioritize this patch. The vulnerability poses particular risk to applications processing untrusted serialized data from external sources.
Technical summary
The Escargot JavaScript engine, Samsung's open-source ECMAScript implementation, contains an uncontrolled recursion vulnerability in its handling of serialized data payloads. When processing specially crafted oversized serialized data, the engine enters recursive processing without adequate depth limits, causing stack exhaustion and denial of service. The vulnerability is present in commit 590345cc6258317c5da850d846ce6baaf2afc2d3. Attack vectors require local access and user interaction, typically through execution of malicious scripts or data files. The fix involves modifications to recursion handling in the serialization/deserialization code path, as proposed in the referenced pull request.
Defensive priority
medium
Recommended defensive actions
- Review and apply pull request #1565 when merged to address uncontrolled recursion in Escargot's serialization handling
- Implement input validation and size limits on serialized data payloads processed by Escargot
- Monitor Escargot repository for official release containing the fix
- Assess applications using Escargot commit 590345cc6258317c5da850d846ce6baaf2afc2d3 or earlier for exposure to crafted serialized data
- Consider sandboxing or resource limits for Escargot execution contexts to mitigate recursion-based denial of service
Evidence notes
Vulnerability confirmed through official Samsung PSIRT disclosure and NVD entry. Affected version identified by specific Git commit hash. Remediation evidence exists via referenced pull request.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47309 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47309
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47309 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47309
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Samsung/escargot/pull/1565
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.