CWE-248: Uncaught Exception
An exception is thrown from a function, but it is not caught.
255 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12423 — Denial of Service - Protocol Manipulation
- CVE-2024-42037 — Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may af
- CVE-2025-53620 — Crashing any Qwik Server
- CVE-2025-0657 — ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range
- CVE-2026-33191 — free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
- CVE-2026-34752 — Haraka affected by DoS via `__proto__` email header
- CVE-2026-32314 — Yamux remote Panic via malformed Data frame with SYN set and len = 262145
- CVE-2026-1507 — Uncaught Exception vulnerability in AVEVA PI Data Archive
- CVE-2025-9124 — Rockwell Automation Compact GuardLogix® 5370 Denial-Of-Service Vulnerability
- CVE-2025-53366 — MCP SDK Vulnerable to FastMCP Server Validation Error, Leading to Denial of Service
- CVE-2025-53365 — MCP Python SDK has Unhandled Exception in Streamable HTTP Transport ,Leading to Denial of Service
- CVE-2025-48997 — Multer vulnerable to Denial of Service via unhandled exception
- CVE-2025-43855 — tRPC 11 WebSocket DoS Vulnerability
- CVE-2025-24883 — go-ethereum has a DoS via malicious p2p message
- CVE-2024-43357 — JavaScript specification issue may lead to type confusion and pointer dereference in implementations
- CVE-2025-67647 — SvelteKit Denial of service and possible SSRF when using prerendering
- CVE-2025-47281 — Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service
- CVE-2026-33203 — SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass
- CVE-2026-31870 — cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header
- CVE-2026-25577 — Emmett has an Unhandled CookieError Exception Causing Denial of Service
Recently published
- CVE-2026-82058 — Unhandled Exception in MongoDB Server JSON Schema Validation Error Generation Leads to Denial of Service
- CVE-2022-51014 — PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding
- CVE-2022-51009 — PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry
- CVE-2026-19534 — undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
- CVE-2026-84947 — undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
- CVE-2026-85014 — undici vulnerable to Denial of Service via WebSocketStream unclean close
- CVE-2026-85024 — undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
- CVE-2026-72644 — Uncaught Exception in Kibana Leading to Denial of Service
- CVE-2026-82417 — qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
- CVE-2026-81517 — MongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL Service
- CVE-2026-77078 — multer vulnerable to Denial of Service via crafted multipart field names
- CVE-2026-55484 — ALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
- CVE-2026-82254 — gitoxide before 0.69.0 Denial of Service via gix-pack
- CVE-2026-54553 — Starlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
- CVE-2026-63403 — Faktory: Unrecovered panic in command handlers allows full-server denial of service
- CVE-2026-79778 — rclone before v1.75.0 Denial of Service via TUS nil-response panic
- CVE-2026-77781 — Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys
- CVE-2026-53530 — ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
- CVE-2026-52731 — ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate
- CVE-2026-52738 — ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks
More specific weaknesses
- CWE-600 — Uncaught Exception in Servlet