Empty exception handler

Empty exception handler

Description

An except block that only executes pass silently ignores the error and may omit necessary failure handling or recovery.

Potential impact

  • A failed security check may be followed by normal processing.
  • Missing diagnostic logs may delay incident response.

Remediation

  • Log the exception and return a clear failure or re-raise it.
  • Catch specific, recoverable exceptions and implement the recovery explicitly.

Examples

Before

python
try:
    value = values[0]
except IndexError:
    pass

After

python
try:
    value = values[0]
except IndexError:
    logger.exception("missing value")
    raise

Explanation:

  • Before: Silently ignores the exception and may omit necessary failure handling or recovery.
  • After: Logs the exception and clearly returns failure to the caller or re-raises it.

References