Falhas do tipo CWE-93

207 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) a usuários ou processos que não deveriam ter acesso. Isso acontece por falta de controle de acesso, logging inadequado, tratamento inseguro de erros ou armazenamento desprotegido. O risco é que um atacante obtém informações suficientes para escalar ataques, falsificar identidades ou comprometer outros sistemas.

Exemplo

Um serviço web retorna a senha do banco de dados em uma mensagem de erro quando a conexão falha; ou uma API expõe IDs internos de usuários em respostas públicas; ou logs de aplicação contêm chaves de API e são armazenados sem proteção de permissões.

Como mitigar

Implemente controle de acesso granular em dados sensíveis, sanitize mensagens de erro para nunca expor detalhes técnicos ao usuário final, criptografe dados em repouso e em trânsito, restrinja permissões de leitura em logs e arquivos de configuração, e faça code review focado em pontos de exposição de dados.

CVE-2026-3234MEDIUMMod_proxy_cluster: mod_proxy_cluster: response body corruption via crlf injectionEPSS 0.3%CVE-2026-9270CRITICALDataDog::DogStatsd versions through 0.07 for Perl allow metric injectionsEPSS 0.3%CVE-2026-46740MEDIUMMojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-50637HIGHMetrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2025-14531MEDIUMcode-projects Rental Management System Log Transaction.java crlf injectionEPSS 0.3%CVE-2025-67735MEDIUMNetty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderEPSS 0.3%CVE-2026-41417MEDIUMNetty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()EPSS 0.3%CVE-2026-1536MEDIUMLibsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition headerEPSS 0.3%CVE-2024-45302MEDIUMCRLF Injection in RestSharp's `RestRequest.AddHeader` methodEPSS 0.3%CVE-2026-47890CRITICALSpring Framework Server Sent Event stream corruption while rendering fragmentsEPSS 0.3%CVE-2026-50292HIGHIn libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrEPSS 0.3%CVE-2026-77634HIGHCakePHP: SmtpTransport vulnerable to CRLF header injectionEPSS 0.3%CVE-2024-45597MEDIUMPluto's http.request allows CR and LF in header valuesEPSS 0.3%CVE-2026-46719MEDIUMNet::Statsd::Lite versions before 0.9.0 for Perl allowed metric injectionsEPSS 0.3%CVE-2026-54511HIGH@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keysEPSS 0.3%CVE-2026-45125MEDIUMMyBB: Email User CRLF injectionEPSS 0.3%CVE-2026-32993HIGHImproper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arEPSS 0.3%CVE-2026-50269LOWAIOHTTP: CRLF injection in multipart headersEPSS 0.3%CVE-2026-77549CRITICALA malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulneraEPSS 0.3%CVE-2026-2442MEDIUMPagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'EPSS 0.3%