Cyber Resilience

CWE · MITRE source

CWE-475Undefined Behavior for Input to API

Abstraction: Base · CVEs in our corpus: 16

The behavior of this function is undefined unless its control parameter is set to a specific value.

Last updated: 21 August 2026 20:21 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SA-11 Developer Testing and Evaluation
  • PR.PS-06
  • ID.RA-01
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-7925 6.27.50.01682020-11-23
CVE-2024-20380 6.17.50.01102024-04-18
CVE-2026-42009 6.17.50.01342026-05-18
CVE-2026-193116.18.10.00422026-08-12
CVE-2025-47865 6.07.50.01562025-06-17
CVE-2024-10569 5.97.50.00642025-03-20
CVE-2026-34379 5.47.10.00282026-04-06
CVE-2023-2253 5.36.50.00942023-06-06
CVE-2026-216904.86.30.00202026-01-07
CVE-2023-52533 4.45.30.00362024-04-08
CVE-2024-3099 4.45.40.00442024-06-06
CVE-2026-8391 4.45.30.00302026-05-12
CVE-2022-29207 4.35.50.00322022-05-20
CVE-2023-4874 3.84.30.00722023-09-09
CVE-2025-47866 3.64.30.00252025-06-17
CVE-2023-4875 2.32.20.00512023-09-09