CWE-394: Unexpected Status Code or Return Value
The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.
Last updated
Overview
CWE-394 (Unexpected Status Code or Return Value) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
13 recorded CVEs are caused by CWE-394 (Unexpected Status Code or Return Value). The highest-severity and most recent are shown first. 1 new CWE-394 CVE has been recorded so far in 2026 (5 in 2025).
- CVE-2025-12516
Lack of Graceful Error Handling - HTTP 5xx Error
Critical · CVSS 10.0 · EPSS 22th2025-10-30 - CVE-2025-12515
Systemic Internal Server Errors - HTTP 500 Response
Critical · CVSS 10.0 · EPSS 22th2025-10-30 - CVE-2026-25085
Copeland XWEB and XWEB Pro Unexpected Status Code or Return Value
High · CVSS 8.6 · EPSS 36th2026-02-27