A10:2025 Mishandling of Exceptional Conditions
New for 2025. Error and exception paths leak information, fail open, or land in inconsistent states. Includes fail-open authentication and logic-flaw error handling.
Member CWEs (24)
- CWE-209 Generation of Error Message Containing Sensitive Information
- CWE-215 Insertion of Sensitive Information Into Debugging Code
- CWE-234 Failure to Handle Missing Parameter
- CWE-235 Improper Handling of Extra Parameters
- CWE-248 Uncaught Exception
- CWE-252 Unchecked Return Value
- CWE-274 Improper Handling of Insufficient Privileges
- CWE-280 Improper Handling of Insufficient Permissions or Privileges
- CWE-369 Divide By Zero
- CWE-390 Detection of Error Condition Without Action
- CWE-391 Unchecked Error Condition
- CWE-394 Unexpected Status Code or Return Value
- CWE-396 Declaration of Catch for Generic Exception
- CWE-397 Declaration of Throws for Generic Exception
- CWE-460 Improper Cleanup on Thrown Exception
- CWE-476 NULL Pointer Dereference
- CWE-478 Missing Default Case in Multiple Condition Expression
- CWE-484 Omitted Break Statement in Switch
- CWE-550 Server-generated Error Message Containing Sensitive Information
- CWE-636 Not Failing Securely ('Failing Open')
- CWE-703 Improper Check or Handling of Exceptional Conditions
- CWE-754 Improper Check for Unusual or Exceptional Conditions
- CWE-755 Improper Handling of Exceptional Conditions
- CWE-756 Missing Custom Error Page
Mapped NIST 800-53 r5 controls (2)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 8,612)
- CVE-2026-77781
- CVE-2026-77641
- CVE-2026-77076
- CVE-2026-76956
- CVE-2026-76928
- CVE-2026-76927
- CVE-2026-76922
- CVE-2026-76905
- CVE-2026-76881
- CVE-2026-76166
- CVE-2026-76014
- CVE-2026-75618
- CVE-2026-75595
- CVE-2026-75013
- CVE-2026-75012
- CVE-2026-74900
- CVE-2026-74879
- CVE-2026-74799
- CVE-2026-73844
- CVE-2026-73555
- CVE-2026-73502
- CVE-2026-73430
- CVE-2026-73429
- CVE-2026-73421
- CVE-2026-73418
- CVE-2026-73288
- CVE-2026-73239
- CVE-2026-73199
- CVE-2026-73088
- CVE-2026-72813
- CVE-2026-72660
- CVE-2026-72582
- CVE-2026-71967
- CVE-2026-70640
- CVE-2026-70639
- CVE-2026-70452
- CVE-2026-69306
- CVE-2026-69247
- CVE-2026-69185
- CVE-2026-68901
- CVE-2026-68746
- CVE-2026-67870
- CVE-2026-67304
- CVE-2026-67302
- CVE-2026-67288
- CVE-2026-67184
- CVE-2026-66774
- CVE-2026-66749
- CVE-2026-66009
- CVE-2026-66008
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1445).