CWE-229: Improper Handling of Values
The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.
The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.
Last updated
CWE-229 (Improper Handling of Values) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
16 recorded CVEs are caused by CWE-229 (Improper Handling of Values). The highest-severity and most recent are shown first. 4 new CWE-229 CVEs have been recorded so far in 2026 (1 in 2025).
Zigbee Router Denial of Service
Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
Math Issue in No-Chicken/Echo-Mate
Kernel: nf_tables: pointer math issue in nft_byteorder_eval()
Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability
Showing 12 of 16 recorded CWE-229 CVEs. Track new ones as they are published and get AI-written analysis and fixes.
Monitor CWE-229 vulnerabilitiesWhat can happen when CWE-229 is exploited.
Unexpected State
Affects: Integrity
Typically introduced during these phases of the software lifecycle.
Common questions about CWE-229.
The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.
16 recorded CVEs are attributed to CWE-229, including CVE-2022-4851, CVE-2025-7964, CVE-2026-45602.
Exploiting CWE-229 can lead to: Unexpected State.
16 recorded CVEs are caused by CWE-229; none are currently in CISA's KEV catalog of actively exploited flaws.
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Get alerted the moment a new CWE-229 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.