CWE-228: Improper Handling of Syntactically Invalid Structure
The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.
17 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-20125 — A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an aut
- CVE-2026-34232 — Firebird: DoS via `op_response` packet from client
- CVE-2026-50103 — Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
- CVE-2026-42100 — DoS in Sparx Pro Cloud Server
- CVE-2026-25657 — Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2025-59174 — Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v
- CVE-2024-53828 — Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2025-47736 — dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not v
- CVE-2025-2529 — IBM Terracotta denial of service
Recently published
- CVE-2026-50103 — Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
- CVE-2025-59174 — Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v
- CVE-2026-25657 — Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-42100 — DoS in Sparx Pro Cloud Server
- CVE-2026-34232 — Firebird: DoS via `op_response` packet from client
- CVE-2024-53828 — Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-20125 — A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an aut
- CVE-2025-2529 — IBM Terracotta denial of service
- CVE-2025-47736 — dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not v