Falhas do tipo CWE-93

207 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) a usuários ou processos que não deveriam ter acesso. Isso acontece por falta de controle de acesso, logging inadequado, tratamento inseguro de erros ou armazenamento desprotegido. O risco é que um atacante obtém informações suficientes para escalar ataques, falsificar identidades ou comprometer outros sistemas.

Exemplo

Um serviço web retorna a senha do banco de dados em uma mensagem de erro quando a conexão falha; ou uma API expõe IDs internos de usuários em respostas públicas; ou logs de aplicação contêm chaves de API e são armazenados sem proteção de permissões.

Como mitigar

Implemente controle de acesso granular em dados sensíveis, sanitize mensagens de erro para nunca expor detalhes técnicos ao usuário final, criptografe dados em repouso e em trânsito, restrinja permissões de leitura em logs e arquivos de configuração, e faça code review focado em pontos de exposição de dados.

CVE-2026-33606MEDIUMMail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync witEPSS 0.2%CVE-2026-8722MEDIUMNet::Async::Statsd::Client versions through 0.005 for Perl allow metric injectionsEPSS 0.2%CVE-2025-54972LOWAn improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 thrEPSS 0.2%CVE-2026-42586MEDIUMNetty: CRLF Injection in Netty Redis Codec EncoderEPSS 0.2%CVE-2026-16455MEDIUMLocal privilege escalation via improper input sanitization in execl() callEPSS 0.2%CVE-2026-35601MEDIUMVikunja has an iCalendar Property Injection via CRLF in CalDAV Task OutputEPSS 0.2%CVE-2026-34975HIGHPlunk has a CRLF Email Header Injection in raw MIME message construction allows authenticated API user to inject arbitrary email headersEPSS 0.2%CVE-2026-15157MEDIUMundici vulnerable to CRLF Injection via blob-like body 'type' propertyEPSS 0.2%CVE-2026-74866MEDIUM@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and nameEPSS 0.2%CVE-2026-13666LOWAn improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.EPSS 0.2%CVE-2026-41570HIGHPHPUnit: Argument injection via newline in PHP INI values forwarded to child processesEPSS 0.2%CVE-2026-82661MEDIUMNodemailer CRLF Injection via List-* Header CommentsEPSS 0.2%CVE-2026-49214MEDIUMguzzlehttp/psr7 has CRLF Injection via URI Host ComponentEPSS 0.2%CVE-2026-3848MEDIUMImproper Neutralization of CRLF Sequences ('CRLF Injection') in GitLabEPSS 0.2%CVE-2026-3634LOWLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type headerEPSS 0.2%CVE-2026-43882MEDIUMWWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event SpoofingEPSS 0.2%CVE-2026-71572MEDIUMJoomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2EPSS 0.2%CVE-2026-48861LOWCRLF injection in HTTP/1 request line via unvalidated method in MintEPSS 0.2%CVE-2026-61477LOWLibvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injectionEPSS 0.2%CVE-2026-94057MEDIUMExim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted dataEPSS 0.2%