CWE-1295: Debug Messages Revealing Unnecessary Information
The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.
21 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-38516 — Aimeos HTML client may potentially reveal sensitive information in error log
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2025-42604 — Detailed Error Response Vulnerability in Meon KYC solutions
- CVE-2025-31001 — WordPress GTM Kit plugin <= 2.4.0 - Sensitive Data Exposure vulnerability
- CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details
- CVE-2025-46775 — A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExt
- CVE-2025-59109 — UART Leaking Sensitive Data in dormakaba registration unit 9002
- CVE-2024-27179 — Session disclosure inside the log files
- CVE-2025-35031 — Medical Informatics Engineering Enterprise Health includes session token in debug output
- CVE-2025-2469 — Debug Messages Revealing Unnecessary Information in GitLab
- CVE-2025-20643 — In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
Recently published
- CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2025-59109 — UART Leaking Sensitive Data in dormakaba registration unit 9002
- CVE-2025-46775 — A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExt
- CVE-2025-35031 — Medical Informatics Engineering Enterprise Health includes session token in debug output
- CVE-2025-42604 — Detailed Error Response Vulnerability in Meon KYC solutions
- CVE-2025-2469 — Debug Messages Revealing Unnecessary Information in GitLab
- CVE-2025-31001 — WordPress GTM Kit plugin <= 2.4.0 - Sensitive Data Exposure vulnerability
- CVE-2025-20643 — In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclo
- CVE-2024-38516 — Aimeos HTML client may potentially reveal sensitive information in error log
- CVE-2024-27179 — Session disclosure inside the log files