Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2026-46740MEDIUMMojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-50637HIGHMetrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2025-14531MEDIUMcode-projects Rental Management System Log Transaction.java crlf injectionEPSS 0.3%CVE-2025-56007MEDIUMCRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with fuEPSS 0.3%CVE-2025-67735MEDIUMNetty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderEPSS 0.3%CVE-2026-41417MEDIUMNetty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()EPSS 0.3%CVE-2024-45302MEDIUMCRLF Injection in RestSharp's `RestRequest.AddHeader` methodEPSS 0.3%CVE-2026-1536MEDIUMLibsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition headerEPSS 0.3%CVE-2026-47890CRITICALSpring Framework Server Sent Event stream corruption while rendering fragmentsEPSS 0.3%CVE-2026-50292HIGHIn libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrEPSS 0.3%CVE-2026-77634HIGHCakePHP: SmtpTransport vulnerable to CRLF header injectionEPSS 0.3%CVE-2024-45597MEDIUMPluto's http.request allows CR and LF in header valuesEPSS 0.3%CVE-2026-46719MEDIUMNet::Statsd::Lite versions before 0.9.0 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-54511HIGH@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keysEPSS 0.3%CVE-2026-45125MEDIUMMyBB: Email User CRLF injectionEPSS 0.3%CVE-2026-50269LOWAIOHTTP: CRLF injection in multipart headersEPSS 0.3%CVE-2026-32993HIGHImproper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arEPSS 0.3%CVE-2026-77549CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraEPSS 0.3%CVE-2026-2442MEDIUMPagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'EPSS 0.3%CVE-2026-45372CRITICALcpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionEPSS 0.3%