CWE-394Base

Unexpected Status Code or Return Value

Draft in the CWE catalog · 15 CVEs mapped

15
CVEs mapped
7.1
Median CVSS
What it is

The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.

Recent examples
5.9cvss
CVE-2026-76956

CVE-2026-76956 - MEDIUM Severity Vulnerability

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.

MEDIUMno explanation yet
0%
epss
8.6cvss
CVE-2026-25085

Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value

A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.

HIGHno explanation yet
0%
epss
7.1cvss
CVE-2025-48510

Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability

⚡ A sneaky return value in AMD uProf could let local attackers dance past KSLR—imagine a VIP pass to your data party without the bouncer noticing! 🎉 Think of KSLR as a security guard who randomly rearranges the furniture at a venue to keep unwanted guests confused. If an attacker knows how the furniture is arranged, they can stroll right in, knowing exactly where the valuables are hidden. This vulnerability could lead to devastating consequences, such as unauthorized access to sensitive data or even service disruptions. With KSLR bypassed, an attacker could manipulate memory addresses, potentially wreaking havoc on the system's confidentiality and availability.

HIGH
0%
epss
The record
Technical detail
CWE ID
CWE-394
Abstraction
Base
Structure
Simple
Status
Draft