CWE-209— Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.— MITRE CWE catalog
643 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-209page 2 of 13
- CVE-2026-84499HIGHCVSS 7.7EG 7.72026-09-23
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node…
- CVE-2024-11625HIGHCVSS 7.7EG 7.72025-01-07
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.…
- CVE-2022-31124HIGHCVSS 7.7EG 7.72022-07-06
openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key files. In versions prior to 0.0.6 if a field of a key is shorter than it is declared to be, the parser raises an error…
- CVE-2021-32775HIGHCVSS 7.7EG 7.72021-07-21
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, a non admin user can get access to many class/field values through GroupBy Dashlet error message. This issue is fixed in versions 2.7.4 and 3.0.0.
- CVE-2020-15125HIGHCVSS 7.7EG 7.72020-07-29
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the A…
- CVE-2023-28117HIGHCVSS 7.6EG 7.62023-03-22
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies valu…
- CVE-2026-47893HIGHCVSS 7.5EG 7.52026-08-27
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Fr…
- CVE-2026-74879HIGHCVSS 7.5EG 7.52026-08-17
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitiv…
- CVE-2026-13182HIGHCVSS 7.5EG 7.52026-07-22
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attacke…
- CVE-2026-42459HIGHCVSS 7.5EG 7.52026-05-27
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Data Management) service. An unauthenticat…
- CVE-2026-45728HIGHCVSS 7.5EG 7.52026-05-19
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the Prett…
- CVE-2026-42552HIGHCVSS 7.5EG 7.52026-05-13
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the full exception message, exception code, and stack trace (including absolute filesystem paths) directly into the HTTP 50…
- CVE-2026-43873HIGHCVSS 7.5EG 7.52026-05-11
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'…
- CVE-2026-40245HIGHCVSS 7.5EG 7.52026-04-16
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disclosure vulnerability in the UDR (Unified Data Repository) service. The handler for GET /nu…
- CVE-2026-29146HIGHCVSS 7.5EG 7.52026-04-09
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 throu…
- CVE-2025-71282HIGHCVSS 7.5EG 7.52026-04-01
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
- CVE-2025-13726HIGHCVSS 7.5EG 7.52026-03-13
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used i…
- CVE-2023-38010HIGHCVSS 7.5EG 7.52026-02-04
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the system.
- CVE-2026-1175HIGHCVSS 7.5EG 7.52026-01-19
A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Directive Handler. Such manipulation leads to information exposure through error message. The…
- CVE-2026-22646HIGHCVSS 7.5EG 7.52026-01-15
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions…
- CVE-2022-50686HIGHCVSS 7.5EG 7.52025-12-18
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potential…
- CVE-2025-26333HIGHCVSS 7.5EG 7.52025-09-25
Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, leading to information exposure.
- CVE-2025-36003HIGHCVSS 7.5EG 7.52025-08-28
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.
- CVE-2025-23320HIGHCVSS 7.5EG 7.52025-08-06
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory limit to be exceeded by sending a very large request. A successful exploit of this vulnera…
- CVE-2025-40718HIGHCVSS 7.5EG 7.52025-07-08
Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to send malformed payloads to generate error messages containing sensitive information.
- CVE-2025-44203HIGHCVSS 7.5EG 7.52025-06-20
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a r…
- CVE-2024-39719HIGHCVSS 7.5EG 7.52024-10-31
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the …
- CVE-2023-46240HIGHCVSS 7.5EG 7.52023-10-31
CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be l…
- CVE-2023-4457HIGHCVSS 7.5EG 7.52023-10-16
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitiz…
- CVE-2023-25948HIGHCVSS 7.5EG 7.52023-07-13
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2023-37306HIGHCVSS 7.5EG 7.52023-06-30
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
- CVE-2023-23837HIGHCVSS 7.5EG 7.52023-04-25
No exception handling vulnerability which revealed sensitive or excessive information to users.
- CVE-2023-25956HIGHCVSS 7.5EG 7.52023-02-24
Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.1.
- CVE-2023-22626HIGHCVSS 7.5EG 7.52023-01-05
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file…
- CVE-2021-38924HIGHCVSS 7.5EG 7.52022-09-14
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the…
- CVE-2021-3513HIGHCVSS 7.5EG 7.52022-08-22
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnera…
- CVE-2022-35715HIGHCVSS 7.5EG 7.52022-08-10
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system…
- CVE-2022-31140HIGHCVSS 7.5EG 7.52022-07-11
Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should not have permission to do so. This is a problem with cases …
- CVE-2022-2062HIGHCVSS 7.5EG 7.52022-06-13
Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.
- CVE-2021-39023HIGHCVSS 7.5EG 7.52022-05-06
IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against …
- CVE-2022-29266HIGHCVSS 7.5EG 7.52022-04-20
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.
- CVE-2021-32937HIGHCVSS 7.5EG 7.52022-04-01
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the …
- CVE-2022-0660HIGHCVSS 7.5EG 7.52022-02-18
Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
- CVE-2017-16629HIGHCVSS 7.5EG 7.52021-08-11
In SapphireIMS 4097_1, it is possible to guess the registered/active usernames of the software from the errors it gives out for each type of user on the Login form. For "Incorrect User" - it gives an error "The application failed to identi…
- CVE-2021-22885HIGHCVSS 7.5EG 7.52021-05-27
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
- CVE-2021-29688HIGHCVSS 7.5EG 7.52021-05-20
IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…
- CVE-2021-20393HIGHCVSS 7.5EG 7.52021-05-14
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks agai…
- CVE-2020-4584HIGHCVSS 7.5EG 7.52020-10-30
IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184…
- CVE-2020-24925HIGHCVSS 7.5EG 7.52020-09-15
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code path is displayed in the browser itself helping the attacker i…
- CVE-2020-13997HIGHCVSS 7.5EG 7.52020-07-28
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
Map vulnerabilities like CWE-209 to your infrastructure
EchelonGraph correlates every CVE — across CWE-209 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →