Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2026-42037MEDIUMAxios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamEPSS 0.3%CVE-2026-20113MEDIUMA vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauEPSS 0.3%CVE-2026-55603HIGHhttp-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`EPSS 0.3%CVE-2026-16313HIGHSg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --exportEPSS 0.3%CVE-2026-44214MEDIUMeventsource-encoder: SSE event injection via unsanitized event and id fieldsEPSS 0.3%CVE-2026-32964MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerabEPSS 0.3%CVE-2026-1527MEDIUMundici is vulnerable to CRLF Injection via upgrade optionEPSS 0.3%CVE-2026-53788MEDIUMrsync < 3.5.0 Newline Injection via name-converter uid/gid mappingEPSS 0.3%CVE-2026-77341MEDIUMcpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writingEPSS 0.3%CVE-2026-93576HIGHIo.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)EPSS 0.3%CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS 0.3%CVE-2026-35504MEDIUMSubnet Solutions PowerSYSTEM Center CRLF injectionEPSS 0.3%CVE-2026-43968MEDIUMCR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1EPSS 0.3%CVE-2026-28753MEDIUMNGINX ngx_mail_proxy_module vulnerabilityEPSS 0.3%CVE-2026-50639MEDIUMMetrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-46741HIGHEtsy::StatsD versions through 1.002002 for Perl allow metric injectionsEPSS 0.3%CVE-2026-84379MEDIUMHTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersEPSS 0.3%CVE-2026-49130MEDIUMMusic Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxxEPSS 0.3%CVE-2026-90937CRITICALfroxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLEPSS 0.3%CVE-2026-46739MEDIUMNet::Statsd versions before 0.13 for Perl allow metric injectionsEPSS 0.3%