Falhas do tipo CWE-347

642 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-9793MEDIUMKeycloak: keycloak: security policy bypass in jwe-encrypted request object processingEPSS 0.2%CVE-2026-22817HIGHJWT Algorithm Confusion via Unsafe Default (HS256) in Hono JWT Middleware Allows Token Forgery and Auth BypassEPSS 0.2%CVE-2026-3706MEDIUMmkj Dropbear S Range Check curve25519.c unpackneg signature verificationEPSS 0.2%CVE-2026-13743LOWImproper verification of cryptographic signature in CubeSpace CW0057 Reaction WheelEPSS 0.2%CVE-2026-18569LOWKeycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokensEPSS 0.2%CVE-2022-24115—Local privilege escalation due to unrestricted loading of unsigned librariesEPSS 0.2%CVE-2026-47191LOWkas checks out SHA-like git branches as valid commitsEPSS 0.2%CVE-2026-86080MEDIUMn8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-OpenEPSS 0.2%CVE-2026-2746MEDIUMMissing PGP Signature TagEPSS 0.2%CVE-2025-9210HIGHMissing JSON Web Token signature validation in Otalio Ship Property Management SystemEPSS 0.2%CVE-2026-18500HIGH@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request keyEPSS 0.2%CVE-2026-55165MEDIUMLemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosureEPSS 0.2%CVE-2024-24694MEDIUMZoom Desktop Client for Windows - Improper Privilege ManagementEPSS 0.2%CVE-2025-43185MEDIUMA downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6. An app may be able to EPSS 0.2%CVE-2026-32883MEDIUMBotan: Missing OCSP Response Signature Verification Allows MitM Certificate Revocation BypassEPSS 0.2%CVE-2022-31807MEDIUMA vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properEPSS 0.2%CVE-2021-34709MEDIUMCisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Image Verification VulnerabilitiesEPSS 0.2%CVE-2022-34459HIGH Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature iEPSS 0.1%CVE-2022-36056MEDIUM Vulnerabilities with blob verification in sigstore cosignEPSS 0.1%CVE-2025-59327HIGHIn CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is presEPSS 0.1%