Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2025-52479HIGHHTTP.jl vulnerable to CR/LF Injection in URIsEPSS 0.4%CVE-2025-53094HIGHESPAsyncWebServer Vulnerable to CRLF Injection in AsyncWebHeader.cppEPSS 0.4%CVE-2026-45070MEDIUMSymfony: Email Header Injection via Non-Token Characters in Mime Parameter NamesEPSS 0.4%CVE-2026-29046CRITICALTinyWeb: HTTP Header Control Character Injection into CGI EnvironmentEPSS 0.4%CVE-2026-59313CRITICALServer Sent Event stream corruption in Spring MVC functional web frameworkEPSS 0.4%CVE-2026-90819MEDIUMa2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splittingEPSS 0.4%CVE-2026-53533MEDIUMaiosmtplib: SMTP command injection via CR/LF in sender/recipient addressEPSS 0.4%CVE-2025-48388HIGHFreeScout Has Insufficient Protection Against CRLF-injectionEPSS 0.4%CVE-2023-26148MEDIUMAll versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attaEPSS 0.4%CVE-2026-24489MEDIUMGakido vulnerable to HTTP Header Injection (CRLF Injection)EPSS 0.4%CVE-2026-28296MEDIUMGvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file pathsEPSS 0.4%CVE-2026-39958MEDIUMoma-topic: name Field in Topic Manifests (topic.json) May Allow CRLF InjectionEPSS 0.4%CVE-2026-22777HIGHComfyUI-Manager is Vulnerable to CRLF Injection in Configuration HandlerEPSS 0.3%CVE-2026-41230HIGHFroxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()EPSS 0.3%CVE-2026-40530HIGHAn improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1EPSS 0.3%CVE-2026-46720HIGHNet::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-50638CRITICALMetrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-1467MEDIUMLibsoup: libsoup: http header injection via specially crafted urls when an http proxy is configuredEPSS 0.3%CVE-2026-3234MEDIUMMod_proxy_cluster: mod_proxy_cluster: response body corruption via crlf injectionEPSS 0.3%CVE-2026-9270CRITICALDataDog::DogStatsd versions through 0.07 for Perl allow metric injectionsEPSS 0.3%