VYPR

CWE-209

Generation of Error Message Containing Sensitive Information

BaseDraftLikelihood: High

Description

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-215 · CAPEC-463 · CAPEC-54 · CAPEC-7

CVEs mapped to this weakness (628)

page 31 of 32
  • CVE-2024-23575MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.

  • CVE-2026-53906HigJul 1, 2026
    risk 0.00cvss 8.2epss 0.01

    MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through…

  • CVE-2026-56331MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors when magic_invite_string is invalid. Attackers can trigger this vulnerability using only the public key by submitting malformed…

  • CVE-2025-36328MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information could be used in further attacks against the system.

  • CVE-2026-47775MedJun 26, 2026
    risk 0.00cvss 6.8epss 0.00

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() functions use AES-256-CBC without an authentication tag (no HMAC, no AEAD). The /callback endpoint…

  • CVE-2026-28675MedMar 6, 2026
    risk 0.00cvss 5.3epss 0.00

    OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints returned raw exception strings to clients. Additionally, login token material was exposed in UI/rendered responses and token…

  • CVE-2026-27643MedFeb 24, 2026
    risk 0.00cvss 5.3epss 0.00

    free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the NEF component reliably leaks internal parsing error details (e.g., invalid character 'n' after top-level…

  • CVE-2025-69253MedFeb 24, 2026
    risk 0.00cvss 5.3epss 0.00

    free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of the User Data Repository are affected by Improper Error Handling with Information Exposure. The NEF component reliably leaks internal parsing error details…

  • CVE-2025-69208MedFeb 23, 2026
    risk 0.00cvss 5.3epss 0.00

    free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerability with Information Exposure. All deployments of free5GC using the…

  • CVE-2026-26957Feb 20, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: Upon further research, the maintainer determined that the behavior described by the CVE record is intended behavior. Per the GitHub Security Advisory: "Libredesk is a single-tenant,…

  • CVE-2025-66549LowDec 5, 2025
    risk 0.00cvss 2.4epss 0.00

    Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators to see it in log files. This…

  • CVE-2023-40457Nov 11, 2024
    risk 0.00cvss —epss 0.00

    The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this…

  • CVE-2024-7038Oct 9, 2024
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-6984HigJul 29, 2024
    risk 0.00cvss 8.8epss 0.00

    An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.

  • CVE-2023-40171CriAug 17, 2023
    risk 0.00cvss 9.1epss 0.01

    Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin - Basic Authentication Provider` plugin encounters an error when attempting to decode a JWT token.…

  • CVE-2023-27587HigMar 13, 2023
    risk 0.00cvss 7.4epss 0.04

    ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error occurs when adding an article, the website shows the user an error message. If the error originates…

  • CVE-2021-3513HigAug 22, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.

  • CVE-2022-24906LowMay 20, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround…

  • CVE-2021-4177MedDec 28, 2021
    risk 0.00cvss 5.3epss 0.01

    livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

  • CVE-2021-32766MedSep 7, 2021
    risk 0.00cvss 5.3epss 0.01

    Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This is problematic in case…