Weaknesses of type CWE-93

207 results

Divulgação de Informações

Fraqueza genérica que engloba qualquer falha onde dados sensíveis (credenciais, tokens, caminhos internos, versões de software) são expostos a usuários ou atacantes que não deveriam ter acesso. O risco varia conforme a sensibilidade da informação vazada e o contexto de exposição.

Example

Um aplicativo web mostra mensagens de erro detalhadas contendo stack traces com paths absolutos do servidor, ou um arquivo de configuração versionado no Git expõe chaves de API. Um atacante coleta essas informações para mapear a infraestrutura ou comprometer credenciais.

How to mitigate

Implemente tratamento genérico de erros (sem revelar detalhes técnicos ao usuário final), remova dados sensíveis de logs públicos, revise permissões de arquivo de configuração, use .gitignore para arquivos sensíveis, e estabeleça reviews regulares de what's exposed em respostas HTTP e mensagens de erro.

CVE-2026-42037MEDIUMAxios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamEPSS 0.3%CVE-2026-20113MEDIUMA vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauEPSS 0.3%CVE-2026-55603HIGHhttp-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`EPSS 0.3%CVE-2026-16313HIGHSg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --exportEPSS 0.3%CVE-2026-44214MEDIUMeventsource-encoder: SSE event injection via unsanitized event and id fieldsEPSS 0.3%CVE-2026-32964MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerabEPSS 0.3%CVE-2026-1527MEDIUMundici is vulnerable to CRLF Injection via upgrade optionEPSS 0.3%CVE-2026-53788MEDIUMrsync < 3.5.0 Newline Injection via name-converter uid/gid mappingEPSS 0.3%CVE-2026-77341MEDIUMcpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writingEPSS 0.3%CVE-2026-93576HIGHIo.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)EPSS 0.3%CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS 0.3%CVE-2026-35504MEDIUMSubnet Solutions PowerSYSTEM Center CRLF injectionEPSS 0.3%CVE-2026-43968MEDIUMCR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1EPSS 0.3%CVE-2026-28753MEDIUMNGINX ngx_mail_proxy_module vulnerabilityEPSS 0.3%CVE-2026-50639MEDIUMMetrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-46741HIGHEtsy::StatsD versions through 1.002002 for Perl allow metric injectionsEPSS 0.3%CVE-2026-84379MEDIUMHTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersEPSS 0.3%CVE-2026-49130MEDIUMMusic Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxxEPSS 0.3%CVE-2026-90937CRITICALfroxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLEPSS 0.3%CVE-2026-46739MEDIUMNet::Statsd versions before 0.13 for Perl allow metric injectionsEPSS 0.3%