Weaknesses of type CWE-93

207 results

Divulgação de Informações

Fraqueza genérica que engloba qualquer falha onde dados sensíveis (credenciais, tokens, caminhos internos, versões de software) são expostos a usuários ou atacantes que não deveriam ter acesso. O risco varia conforme a sensibilidade da informação vazada e o contexto de exposição.

Example

Um aplicativo web mostra mensagens de erro detalhadas contendo stack traces com paths absolutos do servidor, ou um arquivo de configuração versionado no Git expõe chaves de API. Um atacante coleta essas informações para mapear a infraestrutura ou comprometer credenciais.

How to mitigate

Implemente tratamento genérico de erros (sem revelar detalhes técnicos ao usuário final), remova dados sensíveis de logs públicos, revise permissões de arquivo de configuração, use .gitignore para arquivos sensíveis, e estabeleça reviews regulares de what's exposed em respostas HTTP e mensagens de erro.

CVE-2025-52479HIGHHTTP.jl vulnerable to CR/LF Injection in URIsEPSS 0.4%CVE-2025-53094HIGHESPAsyncWebServer Vulnerable to CRLF Injection in AsyncWebHeader.cppEPSS 0.4%CVE-2026-45070MEDIUMSymfony: Email Header Injection via Non-Token Characters in Mime Parameter NamesEPSS 0.4%CVE-2026-29046CRITICALTinyWeb: HTTP Header Control Character Injection into CGI EnvironmentEPSS 0.4%CVE-2026-59313CRITICALServer Sent Event stream corruption in Spring MVC functional web frameworkEPSS 0.4%CVE-2026-90819MEDIUMa2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splittingEPSS 0.4%CVE-2026-53533MEDIUMaiosmtplib: SMTP command injection via CR/LF in sender/recipient addressEPSS 0.4%CVE-2025-48388HIGHFreeScout Has Insufficient Protection Against CRLF-injectionEPSS 0.4%CVE-2023-26148MEDIUMAll versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attaEPSS 0.4%CVE-2026-24489MEDIUMGakido vulnerable to HTTP Header Injection (CRLF Injection)EPSS 0.4%CVE-2026-28296MEDIUMGvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file pathsEPSS 0.4%CVE-2026-39958MEDIUMoma-topic: name Field in Topic Manifests (topic.json) May Allow CRLF InjectionEPSS 0.4%CVE-2026-22777HIGHComfyUI-Manager is Vulnerable to CRLF Injection in Configuration HandlerEPSS 0.3%CVE-2026-41230HIGHFroxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()EPSS 0.3%CVE-2026-40530HIGHAn improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1EPSS 0.3%CVE-2026-46720HIGHNet::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-50638CRITICALMetrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-1467MEDIUMLibsoup: libsoup: http header injection via specially crafted urls when an http proxy is configuredEPSS 0.3%CVE-2026-3234MEDIUMMod_proxy_cluster: mod_proxy_cluster: response body corruption via crlf injectionEPSS 0.3%CVE-2026-9270CRITICALDataDog::DogStatsd versions through 0.07 for Perl allow metric injectionsEPSS 0.3%