CWE-230: Improper Handling of Missing Values
The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.
11 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-20086 — A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE
- CVE-2024-9781 — Improper Handling of Missing Values in Wireshark
- CVE-2024-0208 — Improper Handling of Missing Values in Wireshark
- CVE-2025-23225 — IBM MQ denial of service
- CVE-2026-25659 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-25658 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-1461 — Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
Recently published
- CVE-2026-25659 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-25658 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-20086 — A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE
- CVE-2026-1461 — Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
- CVE-2025-23225 — IBM MQ denial of service
- CVE-2024-9781 — Improper Handling of Missing Values in Wireshark
- CVE-2024-0208 — Improper Handling of Missing Values in Wireshark