Falhas do tipo CWE-93

207 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) a usuários ou processos que não deveriam ter acesso. Isso acontece por falta de controle de acesso, logging inadequado, tratamento inseguro de erros ou armazenamento desprotegido. O risco é que um atacante obtém informações suficientes para escalar ataques, falsificar identidades ou comprometer outros sistemas.

Exemplo

Um serviço web retorna a senha do banco de dados em uma mensagem de erro quando a conexão falha; ou uma API expõe IDs internos de usuários em respostas públicas; ou logs de aplicação contêm chaves de API e são armazenados sem proteção de permissões.

Como mitigar

Implemente controle de acesso granular em dados sensíveis, sanitize mensagens de erro para nunca expor detalhes técnicos ao usuário final, criptografe dados em repouso e em trânsito, restrinja permissões de leitura em logs e arquivos de configuração, e faça code review focado em pontos de exposição de dados.

CVE-2026-45372CRITICALcpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injectionEPSS 0.3%CVE-2026-42037MEDIUMAxios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamEPSS 0.3%CVE-2026-20113MEDIUMA vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauEPSS 0.3%CVE-2026-55603HIGHhttp-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`EPSS 0.3%CVE-2026-16313HIGHSg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --exportEPSS 0.3%CVE-2026-44214MEDIUMeventsource-encoder: SSE event injection via unsanitized event and id fieldsEPSS 0.3%CVE-2026-32964MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerabEPSS 0.3%CVE-2026-1527MEDIUMundici is vulnerable to CRLF Injection via upgrade optionEPSS 0.3%CVE-2026-77341MEDIUMcpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writingEPSS 0.3%CVE-2026-53788MEDIUMrsync < 3.5.0 Newline Injection via name-converter uid/gid mappingEPSS 0.3%CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS 0.3%CVE-2026-93576HIGHIo.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)EPSS 0.3%CVE-2026-35504MEDIUMSubnet Solutions PowerSYSTEM Center CRLF injectionEPSS 0.3%CVE-2026-43968MEDIUMCR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1EPSS 0.3%CVE-2026-50639MEDIUMMetrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injectionsEPSS 0.3%CVE-2026-28753MEDIUMNGINX ngx_mail_proxy_module vulnerabilityEPSS 0.3%CVE-2026-46741HIGHEtsy::StatsD versions through 1.002002 for Perl allow metric injectionsEPSS 0.3%CVE-2026-84379MEDIUMHTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headersEPSS 0.3%CVE-2026-49130MEDIUMMusic Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxxEPSS 0.3%CVE-2026-90937CRITICALfroxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URLEPSS 0.3%