CWE-393: Return of Wrong Status Code
A function or operation returns an incorrect return value or status code that does not indicate the true result of execution, causing the product to modify its behavior based on the incorrect result.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-9058 — Improper Certificate Verification in Szafir SDK
- CVE-2026-55958 — Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
- CVE-2025-5987 — Libssh: invalid return code for chacha20 poly1305 with openssl backend
- CVE-2025-24531 — In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2025-32414 — In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindi
Recently published
- CVE-2026-55958 — Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
- CVE-2026-9058 — Improper Certificate Verification in Szafir SDK
- CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing
- CVE-2025-24531 — In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a
- CVE-2025-5987 — Libssh: invalid return code for chacha20 poly1305 with openssl backend
- CVE-2025-32414 — In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindi