CWE-252Base

Unchecked Return Value

Draft in the CWE catalog · 97 CVEs mapped

97
CVEs mapped
6.7
Median CVSS
What it is

The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.

Recent examples
2.9cvss
CVE-2026-86141

CVE-2026-86141 - LOW Severity Vulnerability

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

LOWno explanation yet
0%
epss
7.5cvss
CVE-2026-19534

CVE-2026-19534 - HIGH Severity Vulnerability

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.

HIGHno explanation yet
0%
epss
7.9cvss
CVE-2026-85649

CVE-2026-85649 - HIGH Severity Vulnerability

(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for example because an incompatible mkpasswd implementation or an environment without yescrypt support is used, the resulting password hash variable can be empty and the build proceeds. The resulting image can therefore contain empty password fields for the root and alpha accounts, potentially permitting passwordless authentication depending on the authentication configuration.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-252
Abstraction
Base
Structure
Simple
Status
Draft
References (6)