CWE-239: Failure to Handle Incomplete Element
The product does not properly handle when a particular element is not completely specified.
Last updated
Overview
CWE-239 (Failure to Handle Incomplete Element) is a variant-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
3 recorded CVEs are caused by CWE-239 (Failure to Handle Incomplete Element). The highest-severity and most recent are shown first. 0 new CWE-239 CVEs have been recorded so far in 2026 (1 in 2025).
Common consequences
What can happen when CWE-239 is exploited.
Varies by Context, Unexpected State
Affects: Integrity, Other
How it happens
When it is introduced
Typically introduced during these phases of the software lifecycle.
Illustrative examples
Real CVEs that MITRE cites as examples of this weakness.
- CVE-2002-1532 — HTTP GET without \r\n\r\n CRLF sequences causes product to wait indefinitely and prevents other users from accessing it.
- CVE-2003-0195 — Partial request is not timed out.
- CVE-2005-2526 — MFV. CPU exhaustion in printer via partial printing request then early termination of connection.
- CVE-2002-1906 — CPU consumption by sending incomplete HTTP requests and leaving the connections open.
Terminology & mappings
Mapped taxonomies
- PLOVER: Incomplete Element
Frequently asked questions
Common questions about CWE-239.
- What is CWE-239?
- The product does not properly handle when a particular element is not completely specified.
- What CVEs are caused by CWE-239?
- 3 recorded CVEs are attributed to CWE-239, including CVE-2025-41724, CVE-2020-10280, CVE-2024-29155.
- What are the consequences of CWE-239?
- Exploiting CWE-239 can lead to: Varies by Context, Unexpected State.
- Is CWE-239 actively exploited?
- 3 recorded CVEs are caused by CWE-239; none are currently in CISA's KEV catalog of actively exploited flaws.
References
- MITRE CWE definition (CWE-239) (opens in a new tab)
- CWE-239 vulnerabilities on NVD (opens in a new tab)
- Learn: What is a CWE?
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Stay ahead of CWE-239
Get alerted the moment a new CWE-239 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.