Weaknesses of type CWE-93

207 results

Divulgação de Informações

Fraqueza genérica que engloba qualquer falha onde dados sensíveis (credenciais, tokens, caminhos internos, versões de software) são expostos a usuários ou atacantes que não deveriam ter acesso. O risco varia conforme a sensibilidade da informação vazada e o contexto de exposição.

Example

Um aplicativo web mostra mensagens de erro detalhadas contendo stack traces com paths absolutos do servidor, ou um arquivo de configuração versionado no Git expõe chaves de API. Um atacante coleta essas informações para mapear a infraestrutura ou comprometer credenciais.

How to mitigate

Implemente tratamento genérico de erros (sem revelar detalhes técnicos ao usuário final), remova dados sensíveis de logs públicos, revise permissões de arquivo de configuração, use .gitignore para arquivos sensíveis, e estabeleça reviews regulares de what's exposed em respostas HTTP e mensagens de erro.

CVE-2026-46740MEDIUMMojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-50637HIGHMetrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2025-14531MEDIUMcode-projects Rental Management System Log Transaction.java crlf injectionEPSS 0.3%CVE-2025-56007MEDIUMCRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with fuEPSS 0.3%CVE-2025-67735MEDIUMNetty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderEPSS 0.3%CVE-2026-41417MEDIUMNetty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()EPSS 0.3%CVE-2024-45302MEDIUMCRLF Injection in RestSharp's `RestRequest.AddHeader` methodEPSS 0.3%CVE-2026-1536MEDIUMLibsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition headerEPSS 0.3%CVE-2026-47890CRITICALSpring Framework Server Sent Event stream corruption while rendering fragmentsEPSS 0.3%CVE-2026-50292HIGHIn libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrEPSS 0.3%CVE-2026-77634HIGHCakePHP: SmtpTransport vulnerable to CRLF header injectionEPSS 0.3%CVE-2024-45597MEDIUMPluto's http.request allows CR and LF in header valuesEPSS 0.3%CVE-2026-46719MEDIUMNet::Statsd::Lite versions before 0.9.0 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-54511HIGH@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keysEPSS 0.3%CVE-2026-45125MEDIUMMyBB: Email User CRLF injectionEPSS 0.3%CVE-2026-50269LOWAIOHTTP: CRLF injection in multipart headersEPSS 0.3%CVE-2026-32993HIGHImproper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arEPSS 0.3%CVE-2026-77549CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraEPSS 0.3%CVE-2026-2442MEDIUMPagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'EPSS 0.3%CVE-2026-45372CRITICALcpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionEPSS 0.3%