What is CWE-908?
MITRE CWEThe product uses or accesses a resource that has not been initialized.
Verify to analyze this CWE entry
A short verification protects the official data source and prevents automated AI abuse.
The product uses or accesses a resource that has not been initialized.
A short verification protects the official data source and prevents automated AI abuse.
The product uses or accesses a resource that has not been initialized.
When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.
Confidentiality
Read Memory, Read Application Data
When reusing a resource such as memory or a program variable, the original contents of that resource may not be cleared before it is sent to an untrusted party.
Availability
DoS: Crash, Exit, or Restart
The uninitialized resource may contain values that cause program flow to change in ways that the programmer did not intend.
These examples illustrate this CWE entry and are not an exhaustive list of related vulnerabilities.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
en