CWE-392Base

Missing Report of Error Condition

Draft in the CWE catalog · 12 CVEs mapped

12
CVEs mapped
7.3
Median CVSS
What it is

The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.

Recent examples
7.4cvss
CVE-2026-42246

CVE-2026-42246 - HIGH Severity Vulnerability

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.

HIGHno explanation yet
0%
epss
5.8cvss
CVE-2026-20005

CVE-2026-20005 - MEDIUM Severity Vulnerability

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete parsing of the SSL handshake ingress packets. An attacker could exploit this vulnerability by sending crafted SSL handshake packets. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when the Snort 3 Detection Engine restarts unexpectedly.

MEDIUMno explanation yet
0%
epss
3.1cvss
CVE-2025-59398

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255>…

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created with StringTooLarge set to Throw.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-392
Abstraction
Base
Structure
Simple
Status
Draft
References (1)