Weaknesses of type CWE-93

207 results

Divulgação de Informações

Fraqueza genérica que engloba qualquer falha onde dados sensíveis (credenciais, tokens, caminhos internos, versões de software) são expostos a usuários ou atacantes que não deveriam ter acesso. O risco varia conforme a sensibilidade da informação vazada e o contexto de exposição.

Example

Um aplicativo web mostra mensagens de erro detalhadas contendo stack traces com paths absolutos do servidor, ou um arquivo de configuração versionado no Git expõe chaves de API. Um atacante coleta essas informações para mapear a infraestrutura ou comprometer credenciais.

How to mitigate

Implemente tratamento genérico de erros (sem revelar detalhes técnicos ao usuário final), remova dados sensíveis de logs públicos, revise permissões de arquivo de configuração, use .gitignore para arquivos sensíveis, e estabeleça reviews regulares de what's exposed em respostas HTTP e mensagens de erro.

CVE-2026-8722MEDIUMNet::Async::Statsd::Client versions through 0.005 for Perl allow metric injectionsEPSS 0.2%CVE-2025-54972LOWAn improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 thrEPSS 0.2%CVE-2026-42586MEDIUMNetty: CRLF Injection in Netty Redis Codec EncoderEPSS 0.2%CVE-2026-16455MEDIUMLocal privilege escalation via improper input sanitization in execl() callEPSS 0.2%CVE-2026-35601MEDIUMVikunja has an iCalendar Property Injection via CRLF in CalDAV Task OutputEPSS 0.2%CVE-2026-34975HIGHPlunk has a CRLF Email Header Injection in raw MIME message construction allows authenticated API user to inject arbitrary email headersEPSS 0.2%CVE-2026-13666LOWAn improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.EPSS 0.2%CVE-2026-74866MEDIUM@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and nameEPSS 0.2%CVE-2026-15157MEDIUMundici vulnerable to CRLF Injection via blob-like body 'type' propertyEPSS 0.2%CVE-2026-41570HIGHPHPUnit: Argument injection via newline in PHP INI values forwarded to child processesEPSS 0.2%CVE-2026-49214MEDIUMguzzlehttp/psr7 has CRLF Injection via URI Host ComponentEPSS 0.2%CVE-2026-82661MEDIUMNodemailer CRLF Injection via List-* Header CommentsEPSS 0.2%CVE-2026-3848MEDIUMImproper Neutralization of CRLF Sequences ('CRLF Injection') in GitLabEPSS 0.2%CVE-2026-3634LOWLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type headerEPSS 0.2%CVE-2026-43882MEDIUMWWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event SpoofingEPSS 0.2%CVE-2026-71572MEDIUMJoomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-48861LOWCRLF injection in HTTP/1 request line via unvalidated method in MintEPSS 0.2%CVE-2026-61477LOWLibvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injectionEPSS 0.2%CVE-2026-94057MEDIUMExim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted dataEPSS 0.2%CVE-2026-86813MEDIUMMetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-ToEPSS 0.2%