Falhas do tipo CWE-1336

254 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, tokens, arquivos internos, estrutura do sistema) a usuários ou atacantes que não deveriam acessá-los. Isso ocorre por falta de controle de acesso adequado, validação insuficiente ou exposição acidental de dados em logs, mensagens de erro ou respostas HTTP.

Exemplo

Um site exibe mensagens de erro detalhadas que revelam caminhos de arquivos e versões de banco de dados; ou uma API retorna dados de outros usuários porque não valida permissões; ou credenciais ficam expostas em comentários do código-fonte publicado.

Como mitigar

Implemente controle de acesso granular (verificar quem acessa o quê); sanitize mensagens de erro (mostrar genéricas ao usuário, logs detalhados apenas internamente); revise e restrinja dados retornados por APIs; escaneie repositórios e logs de produção para credenciais expostas.

CVE-2026-12894HIGHIo.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engineEPSS 0.4%CVE-2025-54287HIGHArbitrary File Read via Template Injection in Snapshot PatternsEPSS 0.4%CVE-2026-75574HIGHGrav before 4.2.2 Remote Code Execution via Email TwigEPSS 0.4%CVE-2025-49142MEDIUMNautobot vulnerable to secrets exposure and data manipulation through Jinja2 templatingEPSS 0.4%CVE-2026-22191MEDIUMBeghelli Sicuro24 SicuroWeb AngularJS Template InjectionEPSS 0.4%CVE-2025-6518MEDIUMPySpur-Dev pyspur Jinja2 Template single_llm_call.py SingleLLMCallNode special elements used in a template engineEPSS 0.4%CVE-2026-46636HIGHTwig: Sandbox method allowlist bypass via `Markup` subclassEPSS 0.4%CVE-2024-58293HIGHAkaunting 3.1.8 Server-Side Template Injection via Multiple Form FieldsEPSS 0.4%CVE-2026-31864MEDIUMJumpServer has a Server-Side Template Injection Leading to RCE via YAML RenderingEPSS 0.3%CVE-2026-33130MEDIUMUptime Kuma: SSTI in Notification Templates Allows Arbitrary File Read (Incomplete Fix for GHSA-vffh-c9pq-4crh)EPSS 0.3%CVE-2026-44916LOWIn OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered without sandboxing.EPSS 0.3%CVE-2025-66435MEDIUMAn SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The funEPSS 0.3%CVE-2025-66436MEDIUMAn SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The EPSS 0.3%CVE-2026-34587HIGHKirby has Server-Side Template Injection (SSTI) via double template resolution in option renderingEPSS 0.3%CVE-2025-46699MEDIUMDell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulEPSS 0.3%CVE-2024-57177HIGHA host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header EPSS 0.3%CVE-2026-27961HIGHAgenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allows RCEEPSS 0.3%CVE-2026-5559MEDIUMAntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template engineEPSS 0.3%CVE-2026-59989CRITICALPhalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lead to RCE)EPSS 0.3%CVE-2026-71291HIGHBolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field RenderingEPSS 0.3%