Fallos del tipo CWE-93

207 resultados

Divulgação de Informações

Uma fraqueza genérica onde a aplicação expõe dados sensíveis (credenciais, tokens, IPs, estrutura interna) a atores não autorizados, seja através de mensagens de erro verbosas, logs acessíveis, respostas HTTP malformadas ou canais inseguros. O risco está em fornecer inteligência ao atacante para explorar outros vetores.

Ejemplo

Um servidor Java expõe stack traces completos em páginas de erro 500, revelando caminhos internos, versões de bibliotecas e nomes de bancos de dados; ou uma API retorna tokens JWT em plaintext em queries de URL em vez de headers, sendo capturados por proxy ou histórico do navegador.

Cómo mitigar

Implemente tratamento genérico de exceções (não exponha detalhes técnicos ao cliente), sanitize mensagens de erro, configure logs fora do escopo público, use HTTPS obrigatório, e revise respostas HTTP quanto a dados sensíveis. Em produção, desabilite debug mode e verbose error messages.

CVE-2026-9679MEDIUMundici vulnerable to HTTP header injection via Set-Cookie percent-decodingEPSS 0.3%CVE-2026-34458CRITICALSandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnlyEPSS 0.3%CVE-2026-71573MEDIUMJoomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-90767HIGHFroxlor before 2.3.12 SSH Key Injection via authorized_keysEPSS 0.2%CVE-2026-59921MEDIUMNetty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderEPSS 0.2%CVE-2026-33635MEDIUMiCalendar has ICS injection via unsanitized URI property valuesEPSS 0.2%CVE-2026-59920MEDIUMNetty: STOMP CONNECT Frame Header InjectionEPSS 0.2%CVE-2026-71311MEDIUMrclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves NewlinesEPSS 0.2%CVE-2026-57511MEDIUMSuperPlane < 0.30.0 SMTP Header Injection via Webhook Event TitleEPSS 0.2%CVE-2026-2400MEDIUMCWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reEPSS 0.2%CVE-2026-55766MEDIUMguzzlehttp/psr7: CRLF Injection in HTTP Start-Line SerializationEPSS 0.2%CVE-2026-26962MEDIUMRack: Header injection in multipart requestsEPSS 0.2%CVE-2026-8788HIGHNet::Statsd::Lite versions through 0.10.0 for Perl allowed metric injectionsEPSS 0.2%CVE-2026-3633LOWLibsoup: libsoup: header and http request injection via crlf injectionEPSS 0.2%CVE-2026-70615HIGHboringproxy 0.10.0 SSH authorized_keys Injection via Tunnel CreationEPSS 0.2%CVE-2025-6175HIGHCRLF Injection in DECE Software's GeodiEPSS 0.2%CVE-2026-0673MEDIUMElement Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header InjectionEPSS 0.2%CVE-2022-50682MEDIUMKentico Xperience <= 13.0.79 Routing Engine CRLF InjectionEPSS 0.2%CVE-2026-49756LOWMultipart form-data header injection in Req via unescaped name/filename/content_typeEPSS 0.2%CVE-2026-33606MEDIUMMail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync witEPSS 0.2%