CWE-221: Information Loss or Omission
The product does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.
Last updated
Overview
CWE-221 (Information Loss or Omission) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
1 recorded CVEs are caused by CWE-221 (Information Loss or Omission). The highest-severity and most recent are shown first. 1 new CWE-221 CVE has been recorded so far in 2026.
Common consequences
What can happen when CWE-221 is exploited.
Hide Activities
Affects: Non-Repudiation
How it happens
When it is introduced
Typically introduced during these phases of the software lifecycle.