Falhas do tipo CWE-1336

254 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, tokens, arquivos internos, estrutura do sistema) a usuários ou atacantes que não deveriam acessá-los. Isso ocorre por falta de controle de acesso adequado, validação insuficiente ou exposição acidental de dados em logs, mensagens de erro ou respostas HTTP.

Exemplo

Um site exibe mensagens de erro detalhadas que revelam caminhos de arquivos e versões de banco de dados; ou uma API retorna dados de outros usuários porque não valida permissões; ou credenciais ficam expostas em comentários do código-fonte publicado.

Como mitigar

Implemente controle de acesso granular (verificar quem acessa o quê); sanitize mensagens de erro (mostrar genéricas ao usuário, logs detalhados apenas internamente); revise e restrinja dados retornados por APIs; escaneie repositórios e logs de produção para credenciais expostas.

CVE-2026-3714MEDIUMOpenCart Incomplete Fix CVE-2024-36694 template.php save special elements used in a template engineEPSS 0.3%CVE-2026-26938HIGHImproper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading to Server-Side Request Forgery (SSRF)EPSS 0.3%CVE-2022-47896MEDIUMIn JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.EPSS 0.3%CVE-2026-25731HIGHCalibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML ExportEPSS 0.3%CVE-2026-13297HIGHSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2026-81910MEDIUMConcrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style ValuesEPSS 0.2%CVE-2026-78140MEDIUMDromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engineEPSS 0.2%CVE-2026-82958HIGHIn Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command byEPSS 0.2%CVE-2026-46439HIGHcompliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)EPSS 0.2%CVE-2026-5987MEDIUMSanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engineEPSS 0.2%CVE-2026-77129HIGHServer-Side Template Injection in extension "Event management and registration" (sf_event_mgt)EPSS 0.2%CVE-2026-8740MEDIUMSanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engineEPSS 0.2%CVE-2026-18632MEDIUMlanggenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engineEPSS 0.2%CVE-2024-39766HIGHImproper neutralization of special elements used in SQL command in some Intel(R) Neural Compressor software before version v3.0 may allow anEPSS 0.2%CVE-2026-71239HIGHDjangoCRM - Server-Side Template Injection in Mass Mail Message RenderingEPSS 0.2%CVE-2026-73505HIGHOh My Posh: Arbitrary command execution via template injection in the path segmentEPSS 0.2%CVE-2026-41713HIGHPrompt Injection via Memory Poisoning in PromptChatMemoryAdvisorEPSS 0.2%CVE-2026-75036MEDIUMFleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessingEPSS 0.2%CVE-2026-63728HIGHGitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template FeatureEPSS 0.2%CVE-2026-57170HIGHTrestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)EPSS 0.2%