Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2026-8722MEDIUMNet::Async::Statsd::Client versions through 0.005 for Perl allow metric injectionsEPSS 0.2%CVE-2025-54972LOWAn improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 thrEPSS 0.2%CVE-2026-42586MEDIUMNetty: CRLF Injection in Netty Redis Codec EncoderEPSS 0.2%CVE-2026-16455MEDIUMLocal privilege escalation via improper input sanitization in execl() callEPSS 0.2%CVE-2026-35601MEDIUMVikunja has an iCalendar Property Injection via CRLF in CalDAV Task OutputEPSS 0.2%CVE-2026-34975HIGHPlunk has a CRLF Email Header Injection in raw MIME message construction allows authenticated API user to inject arbitrary email headersEPSS 0.2%CVE-2026-13666LOWAn improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.EPSS 0.2%CVE-2026-74866MEDIUM@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and nameEPSS 0.2%CVE-2026-15157MEDIUMundici vulnerable to CRLF Injection via blob-like body 'type' propertyEPSS 0.2%CVE-2026-41570HIGHPHPUnit: Argument injection via newline in PHP INI values forwarded to child processesEPSS 0.2%CVE-2026-49214MEDIUMguzzlehttp/psr7 has CRLF Injection via URI Host ComponentEPSS 0.2%CVE-2026-82661MEDIUMNodemailer CRLF Injection via List-* Header CommentsEPSS 0.2%CVE-2026-3848MEDIUMImproper Neutralization of CRLF Sequences ('CRLF Injection') in GitLabEPSS 0.2%CVE-2026-3634LOWLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type headerEPSS 0.2%CVE-2026-43882MEDIUMWWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event SpoofingEPSS 0.2%CVE-2026-71572MEDIUMJoomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-48861LOWCRLF injection in HTTP/1 request line via unvalidated method in MintEPSS 0.2%CVE-2026-61477LOWLibvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injectionEPSS 0.2%CVE-2026-94057MEDIUMExim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted dataEPSS 0.2%CVE-2026-86813MEDIUMMetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-ToEPSS 0.2%