CWE-248

Uncaught Exception

Parent: CWE-705 - Incorrect Control Flow Scoping

An exception is thrown from a function, but it is not caught.

242 vulnerabilities with CWE-248
CVE-2026-65834 MEDIUM
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
CVSS 6.8
CVE-2026-13697 HIGH
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVSS 7.4
CVE-2026-47219 HIGH
find-my-way is Vulnerable to DDoS with HTTP2
CVSS 7.5
CVE-2026-64612 HIGH
Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png
CVSS 7.5
CVE-2026-63747 HIGH
SurrealDB before 3.1.0 Denial of Service via malformed RPC use
CVSS 7.5
CVE-2026-62994 LOW
CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
CVSS 3.7
CVE-2026-48069 HIGH
@grpc/grps-js: An incoming malformed compressed message can cause a client or server crash
CVSS 7.5
CVE-2026-48068 HIGH
@grpc/grps-js: A malformed request can cause a server crash
CVSS 7.5
CVE-2026-48038 MEDIUM
joi: Uncaught RangeError on deeply nested input through recursive `link()` schemas
CVSS 5.3
CVE-2026-47480 HIGH
Nvidia Triton Inference Server < 26.04 - Uncaught Exception
CVSS 7.5
CVE-2026-50328 HIGH
Microsoft Windows 10 Version 1607 - Windows Server Update Service (WSUS) Tampering Vulnerability
CVSS 7.5
CVE-2026-59162 HIGH
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVSS 7.5
CVE-2026-55780 LOW
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
CVE-2026-54775 MEDIUM
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVSS 6.5
CVE-2026-58208 MEDIUM
NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
CVSS 6.8
CVE-2026-59892 HIGH
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
CVSS 7.5
CVE-2026-59875 MEDIUM
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVSS 5.3
CVE-2026-27844 LOW
Gallagher Controller 7000 And 6000 - Uncaught Exception
CVSS 2.7
CVE-2026-27790 LOW
Gallagher T-20 Readers - Uncaught Exception
CVSS 2.7
CVE-2026-14631 MEDIUM
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
CVSS 5.3
CVE-2026-54908 MEDIUM
Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
CVE-2026-14181 HIGH
@fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths
CVSS 7.5
CVE-2026-50129 HIGH
Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER
CVSS 7.5
CVE-2026-55517 MEDIUM
Deno: Denial of service via non-ASCII bytes in WebSocket response headers
CVSS 4.3
CVE-2026-12644 MEDIUM
Ts-deepmerge < 8.0.0 - Uncaught Exception
CVSS 5.3
Details
Vulnerabilities 242