CWE · MITRE source
CWE-1286Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
Often, complex inputs are expected to follow a particular syntax, which is either assumed by the input itself, or declared within metadata such as headers. The syntax could be for data exchange formats, markup languages, or even programming languages. When untrusted input is not properly validated for the expected syntax, attackers could cause parsing failures, trigger unexpected errors, or expose latent vulnerabilities that might not be directly exploitable if the input had conformed to the syntax.
Last updated: 21 August 2026 20:21 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 2 mapping(s) from 1 framework(s): CAPEC 2 (partial)
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
—
—
V1.1.1V1.4.2V2.1.1V2.2.2
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-7954 UPD | 9.9 | 9.8 | 0.9005 | 2024-08-23 |
CVE-2021-28812 UPD | 6.9 | 8.8 | 0.0155 | 2021-06-03 |
CVE-2021-31988 UPD | 6.7 | 8.8 | 0.0095 | 2021-10-05 |
CVE-2024-51982 UPD | 6.7 | 7.5 | 0.0824 | 2025-06-25 |
CVE-2024-51983 UPD | 6.7 | 7.5 | 0.0905 | 2025-06-25 |
CVE-2025-13878 UPD | 6.7 | 7.5 | 0.0836 | 2026-01-21 |
CVE-2025-41719 UPD | 6.6 | 8.8 | 0.0051 | 2025-10-22 |
CVE-2026-25513 UPD | 6.6 | 8.8 | 0.0047 | 2026-02-04 |
CVE-2026-50131 UPD | 6.5 | 8.6 | 0.0035 | 2026-06-10 |
CVE-2022-1941 UPD | 6.1 | 7.5 | 0.0121 | 2022-09-22 |
CVE-2022-22192 UPD | 6.0 | 7.5 | 0.0074 | 2022-10-18 |
CVE-2024-3384 UPD | 6.0 | 7.5 | 0.0089 | 2024-04-10 |
CVE-2025-22868 UPD | 6.0 | 7.5 | 0.0084 | 2025-02-26 |
CVE-2026-21527 UPD | 6.0 | 6.5 | 0.0768 | 2026-02-10 |
CVE-2026-25679 UPD | 6.0 | 7.5 | 0.0073 | 2026-03-06 |
CVE-2026-42579 UPD | 6.0 | 7.5 | 0.0101 | 2026-05-13 |
CVE-2026-7307 UPD | 6.0 | 7.5 | 0.0074 | 2026-05-19 |
CVE-2021-31987 UPD | 5.9 | 7.5 | 0.0089 | 2021-10-05 |
CVE-2023-28985 UPD | 5.9 | 7.5 | 0.0063 | 2023-07-14 |
CVE-2023-32649 UPD | 5.9 | 7.5 | 0.0053 | 2023-09-19 |
CVE-2024-21595 UPD | 5.9 | 7.5 | 0.0054 | 2024-01-12 |
CVE-2024-21616 UPD | 5.9 | 7.5 | 0.0053 | 2024-01-12 |
CVE-2024-0218 UPD | 5.9 | 7.5 | 0.0055 | 2024-04-10 |
CVE-2024-21598 UPD | 5.9 | 7.5 | 0.0057 | 2024-04-12 |
CVE-2024-39542 UPD | 5.9 | 7.5 | 0.0047 | 2024-07-11 |