CWE-228Class

Improper Handling of Syntactically Invalid Structure

Incomplete in the CWE catalog · 17 CVEs mapped

17
CVEs mapped
6.5
Median CVSS
What it is

The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.

Recent examples
7.1cvss
CVE-2026-50103

Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850

A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.

HIGHno explanation yet
0%
epss
7.1cvss
CVE-2025-59174

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may…

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

HIGHno explanation yet
0%
epss
7.1cvss
CVE-2026-25657

Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-228
Abstraction
Class
Structure
Simple
Status
Incomplete