CWE · MITRE source
CWE-141Improper Neutralization of Parameter/Argument Delimiters
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as parameter or argument delimiters when they are sent to a downstream component.
As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.
Last updated: 21 August 2026 14:15 UTC
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
Detect
Catch it (CSF Detect / Respond)
—
Harden
Shrink the surface (DISA STIG)
—
Validate
Prove the fix (OWASP ASVS)
—
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2022-29873 UPD | 7.6 | 9.8 | 0.0187 | 2022-05-20 |
CVE-2023-28815 UPD | 7.6 | 9.8 | 0.0146 | 2025-10-17 |
CVE-2022-41665 UPD | 7.5 | 9.8 | 0.0110 | 2022-10-11 |
CVE-2020-7868 UPD | 7.2 | 9.6 | 0.0270 | 2021-06-29 |
CVE-2022-29872 UPD | 6.8 | 8.8 | 0.0141 | 2022-05-20 |
CVE-2024-0840 UPD | 6.7 | 8.8 | 0.0088 | 2024-04-29 |
CVE-2026-20200 | 6.7 | 8.8 | 0.0084 | 2026-08-05 |
CVE-2026-19594 | 6.1 | 8.1 | 0.0040 | 2026-08-12 |
CVE-2025-31329 UPD | 4.6 | 6.2 | 0.0034 | 2025-05-13 |
CVE-2025-20338 UPD | 4.5 | 6.0 | 0.0015 | 2025-09-24 |