Skip to main content
JG is here with you ✨
A10:2025

Mishandling of Exceptional Conditions

Error Handling, Edge Cases & Fail States

NEW in 2025

What is Mishandling of Exceptional Conditions?

This NEW category in OWASP 2025 covers improper handling of errors, edge cases, and abnormal conditions. When applications fail to anticipate exceptional scenarios, they may crash, expose sensitive information, or enter insecure states.

Error HandlingEdge CasesFail StatesResource Limits

Why a New Category?

Previously scattered across other categories, exceptional condition handling has become critical enough to warrant its own focus. Modern applications face:

Increased Complexity

Microservices, async operations, and distributed systems create more failure points

API-First Architecture

APIs must handle malformed requests, timeouts, and unexpected inputs gracefully

Verbose Error Messages

Exposing internal details in errors

Null/Undefined Handling

Crashes from missing data

Integer Overflow

Arithmetic exceeding bounds

Resource Exhaustion

Unbounded memory/CPU usage

Race Conditions

Concurrent state corruption

Fail Open

Granting access on errors

Related CWE Entries

Built by an OWASP Member • Part of the OWASP Web Security Lab Series

Open to AI-Focused Roles

AI Sales • AI Strategy • AI Success • Creative Tech • Toronto / Remote

Let's connect →
Terms of ServiceLicense AgreementPrivacy Policy
Copyright © 2026 JMFG. All rights reserved.