Empty exception handler

Empty exception handler

Description

An empty catch block, or one that only logs without handling failure, may hide the failure from the caller and let processing continue in an invalid state. Logs help diagnosis but do not replace a failure response or recovery action.

Potential impact

  • Processing may continue as if a security check had succeeded.
  • Failures in file operations, authentication or cryptography may be hidden.

Remediation

  • Log the exception and return failure to the caller or rethrow it.
  • Handle only specific recoverable exceptions and implement the recovery action explicitly.

Examples

Before

javascript
try {
  verifySignature(input);
} catch (err) {
}

After

javascript
try {
  verifySignature(input);
} catch (err) {
  logger.error({ err }, "signature verification failed");
  throw err;
}

Explanation:

  • Before: The empty handler suppresses the failure, allowing subsequent processing to continue. Logging alone would not provide a failure response or recovery.
  • After: The error is logged and rethrown so processing does not continue as successful. Redact sensitive log values and restrict log access.

References