CWE-391: Unchecked Error Condition
[PLANNED FOR DEPRECATION. SEE MAINTENANCE NOTES AND CONSIDER CWE-252, CWE-248, OR CWE-1069.] Ignoring exceptions and other error conditions may allow an attacker to induce unexpected behavior unnoticed.
25 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-71325 — picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
- CVE-2026-74900 — openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
- CVE-2024-23326 — Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
- CVE-2024-52316 — Apache Tomcat: Authentication bypass when using Jakarta Authentication API
Recently published
- CVE-2026-74900 — openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
- CVE-2025-71325 — picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
- CVE-2024-52316 — Apache Tomcat: Authentication bypass when using Jakarta Authentication API
- CVE-2024-23326 — Envoy incorrectly accepts HTTP 200 response for entering upgrade mode