CWE-209: Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
376 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-68110 — ChurchCRM discloses database information on error message
- CVE-2025-62168 — Squid vulnerable to information disclosure via authentication credential leakage in error handling
- CVE-2025-47813 — loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a
- CVE-2026-33192 — free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
- CVE-2025-71282 — XenForo Path Disclosure via open_basedir Exceptions
- CVE-2025-36003 — IBM Security Verify Governance Identity Manager information disclosure
- CVE-2025-23320 — NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
- CVE-2024-23689 — ClickHouse Client Certificate Password Exposure
- CVE-2026-74879 — openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint
- CVE-2025-12773 — Plain password is generated in the audit logs while executing update-reports-purge-settings.sh script with Brocade SANnav before 2.4.0a
- CVE-2024-51560 — Improper Error Handling Vulnerability in Wave 2.0
- CVE-2025-62840 — HBS 3 Hybrid Backup Sync
- CVE-2026-41644 — monetr is vulnerable to server-side request forgery in Lunch Flow link creation and refresh
- CVE-2026-33065 — free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request
- CVE-2026-30835 — Parse Server: Malformed `$regex` query leaks database error details in API response
- CVE-2026-27004 — OpenClaw session tool visibility hardening and Telegram webhook secret fallback
- CVE-2026-1175 — birkir prime GraphQL Directive graphql information exposure
- CVE-2025-66594 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed
- CVE-2025-61959 — Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information
- CVE-2025-54291 — Project existence disclosure in LXD images API
Recently published
- CVE-2026-11873 — Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure
- CVE-2026-82739 — Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error
- CVE-2026-82733 — Route handler return value echoed into AshTypescript error response
- CVE-2026-77950 — RPC error handler fails open in AshTypescript, disclosing unredacted errors
- CVE-2026-82727 — AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error message
- CVE-2026-75760 — AshAi vectorize change leaks raw embedding-provider errors, including credentials, in a user-facing error
- CVE-2026-82580 — AshAi echoes raw tool exception messages into the conversation, disclosing internal details
- CVE-2026-78693 — Incomplete redaction re-attaches the original error path in AshGraphql, leaking internal field names
- CVE-2026-21809 — HCL BigFix Quantum Risk Analyzer is affected by generating error messages with sensitive information
- CVE-2026-79777 — rclone before v1.75.0 Information Disclosure via RC API
- CVE-2026-8173 — Information Disclosure via 'Copy learned MAC Addresses' Function
- CVE-2026-33333 — Combodo iTop: Information disclosure in ajax.render.php
- CVE-2026-77076 — n8n before 1.123.69 Credential Leak via GraphQL Node Error
- CVE-2026-53458 — Blueprint Studio API exposed internal exception details
- CVE-2026-74879 — openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint
- CVE-2026-73844 — CKAN MCP Server: Information disclosure via verbose error reflection
- CVE-2026-73555 — vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
- CVE-2026-56620 — HCL BigFix Mobile is vulnerable to information disclosure
- CVE-2026-43630 — llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
- CVE-2026-47622 — NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con