CWE-665: Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Last updated
Overview
This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.
Real-world CVEs
137 recorded CVEs are caused by CWE-665 (Improper Initialization), including 3 in CISA's KEV (Known Exploited Vulnerabilities) catalog. KEVs are shown first. 8 new CWE-665 CVEs have been recorded so far in 2026 (12 in 2025).