CWE-230: Improper Handling of Missing Values

low-risk

The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.

Abstraction: Variant

Common Consequences

Integrity Unexpected State

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2024-10508 9.8 15.3%
CVE-2024-6237 6.5 0.8%
CVE-2024-11024 9.8 0.3%
CVE-2025-23225 6.5 0.2%
CVE-2024-9781 7.8 0.2%
CVE-2026-20086 8.6 0.1%
CVE-2023-1697 6.5 0.1%
CVE-2026-1461 6.5 0.1%
CVE-2024-0208 7.8 0.0%
CVE-2024-0048 7.8 0.0%
4
/ 100
low-risk
Active Threat 4/50 · Minimal
Exploit Availability 0/50 · Minimal