Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2026-12357HIGHHeimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-35520HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline InjectionEPSS 0.7%CVE-2024-40324CRITICALA CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fielEPSS 0.7%CVE-2026-35521HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dhcp.hosts Newline InjectionEPSS 0.7%CVE-2026-35518HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline InjectionEPSS 0.7%CVE-2024-32986CRITICALArbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox EPSS 0.7%CVE-2026-48019HIGHCRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relayEPSS 0.7%CVE-2026-1714HIGHShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX ActionEPSS 0.7%CVE-2026-75925CRITICALIXON VPN Client CRLF InjectionEPSS 0.7%CVE-2024-5193MEDIUMRitlabs TinyWeb Server Request crlf injectionEPSS 0.7%CVE-2025-11468MEDIUMFolding email comments of unfoldable characters doesn't preserve parenthesisEPSS 0.6%CVE-2026-45067MEDIUMSymfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\AddressEPSS 0.6%CVE-2026-12127MEDIUMWPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display NameEPSS 0.6%CVE-2026-6351HIGHOpenfind|MailGates/MailAudit - CRLF InjectionEPSS 0.6%CVE-2026-1299MEDIUMemail BytesGenerator header injection due to unquoted newlinesEPSS 0.6%CVE-2026-33128HIGHh3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream FieldsEPSS 0.6%CVE-2026-11373CRITICALNet::Statsite::Client versions through 1.1.0 for Perl allow metric injectionsEPSS 0.6%CVE-2026-1502MEDIUMHTTP client proxy tunnel headers not validated for CR/LFEPSS 0.6%CVE-2024-51501CRITICALCRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributesEPSS 0.6%CVE-2026-75484MEDIUMHTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in BanditEPSS 0.5%