Weaknesses of type CWE-93

207 results

Divulgação de Informações

Fraqueza genérica que engloba qualquer falha onde dados sensíveis (credenciais, tokens, caminhos internos, versões de software) são expostos a usuários ou atacantes que não deveriam ter acesso. O risco varia conforme a sensibilidade da informação vazada e o contexto de exposição.

Example

Um aplicativo web mostra mensagens de erro detalhadas contendo stack traces com paths absolutos do servidor, ou um arquivo de configuração versionado no Git expõe chaves de API. Um atacante coleta essas informações para mapear a infraestrutura ou comprometer credenciais.

How to mitigate

Implemente tratamento genérico de erros (sem revelar detalhes técnicos ao usuário final), remova dados sensíveis de logs públicos, revise permissões de arquivo de configuração, use .gitignore para arquivos sensíveis, e estabeleça reviews regulares de what's exposed em respostas HTTP e mensagens de erro.

CVE-2026-9679MEDIUMundici vulnerable to HTTP header injection via Set-Cookie percent-decodingEPSS 0.3%CVE-2026-34458CRITICALSandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnlyEPSS 0.3%CVE-2026-71573MEDIUMJoomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-90767HIGHFroxlor before 2.3.12 SSH Key Injection via authorized_keysEPSS 0.2%CVE-2026-59921MEDIUMNetty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderEPSS 0.2%CVE-2026-33635MEDIUMiCalendar has ICS injection via unsanitized URI property valuesEPSS 0.2%CVE-2026-59920MEDIUMNetty: STOMP CONNECT Frame Header InjectionEPSS 0.2%CVE-2026-71311MEDIUMrclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves NewlinesEPSS 0.2%CVE-2026-57511MEDIUMSuperPlane < 0.30.0 SMTP Header Injection via Webhook Event TitleEPSS 0.2%CVE-2026-2400MEDIUMCWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reEPSS 0.2%CVE-2026-55766MEDIUMguzzlehttp/psr7: CRLF Injection in HTTP Start-Line SerializationEPSS 0.2%CVE-2026-26962MEDIUMRack: Header injection in multipart requestsEPSS 0.2%CVE-2026-8788HIGHNet::Statsd::Lite versions through 0.10.0 for Perl allowed metric injectionsEPSS 0.2%CVE-2026-3633LOWLibsoup: libsoup: header and http request injection via crlf injectionEPSS 0.2%CVE-2026-70615HIGHboringproxy 0.10.0 SSH authorized_keys Injection via Tunnel CreationEPSS 0.2%CVE-2025-6175HIGHCRLF Injection in DECE Software's GeodiEPSS 0.2%CVE-2026-0673MEDIUMElement Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header InjectionEPSS 0.2%CVE-2022-50682MEDIUMKentico Xperience <= 13.0.79 Routing Engine CRLF InjectionEPSS 0.2%CVE-2026-49756LOWMultipart form-data header injection in Req via unescaped name/filename/content_typeEPSS 0.2%CVE-2026-33606MEDIUMMail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync witEPSS 0.2%