CWE-686: Function Call With Incorrect Argument Type
The product calls a function, procedure, or routine, but the caller specifies an argument that is the wrong data type, which may lead to resultant weaknesses.
Last updated
Overview
This weakness is most likely to occur in loosely typed languages, or in strongly typed languages in which the types of variable arguments cannot be enforced at compilation time, or where there is implicit casting.
Real-world CVEs
5 recorded CVEs are caused by CWE-686 (Function Call With Incorrect Argument Type). The highest-severity and most recent are shown first. 2 new CWE-686 CVEs have been recorded so far in 2026 (1 in 2025).
- CVE-2025-14330
JIT miscompilation in the JavaScript Engine: JIT component
Critical · CVSS 9.8 · EPSS 20th2025-12-09 - CVE-2026-8389
JIT miscompilation in the JavaScript Engine: JIT component
High · CVSS 8.8 · EPSS 4th2026-05-12 - CVE-2026-33783
Junos OS Evolved: PTX Series: If SRTE tunnels provisioned via PCEP are present and specific gRPC queries are received evo-aftmand crashes