CWE-253: Incorrect Check of Function Return Value
The product incorrectly checks a return value from a function, which prevents it from detecting errors or exceptional conditions.
23 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-0648 — The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_
- CVE-2025-57767 — Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
- CVE-2024-1622 — Routinator terminates when RTR connection is reset too quickly after opening
- CVE-2026-35091 — Corosync: corosync: denial of service and information disclosure via crafted udp packet
- CVE-2024-32475 — Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes
- CVE-2026-46419 — Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value i
- CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
- CVE-2026-5818 — MCU Firmware Update Authentication Bypass on Caliptra Core
- CVE-2026-59847 — Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
- CVE-2026-35340 — uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
- CVE-2026-35339 — uutils coreutils chmod False Success Exit Code in Recursive Mode
- CVE-2026-43863 — mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
- CVE-2025-54090 — Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
Recently published
- CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
- CVE-2026-59847 — Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
- CVE-2026-5818 — MCU Firmware Update Authentication Bypass on Caliptra Core
- CVE-2026-46419 — Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value i
- CVE-2026-43863 — mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
- CVE-2026-35340 — uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
- CVE-2026-35339 — uutils coreutils chmod False Success Exit Code in Recursive Mode
- CVE-2026-35091 — Corosync: corosync: denial of service and information disclosure via crafted udp packet
- CVE-2026-0648 — The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_
- CVE-2025-57767 — Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
- CVE-2025-54090 — Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64
- CVE-2024-32475 — Envoy RELEASE_ASSERT using auto_sni with :authority header > 255 bytes
- CVE-2024-1622 — Routinator terminates when RTR connection is reset too quickly after opening