CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
69 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-32891 — Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS
- CVE-2025-65965 — Grype has a credential disclosure vulnerability in its JSON output
- CVE-2026-42880 — ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
- CVE-2026-34214 — Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
- CVE-2026-85094 — The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privilege
- CVE-2026-39937 — Global vanishing does not completely remove user email
- CVE-2024-43384 — Phoenix Contact: Improper removal of sensitive information in MGUARD products
- CVE-2026-43824 — In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
- CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
- CVE-2026-46657 — Bludit's persistent authentication tokens not revoked upon account disablement
- CVE-2026-43528 — OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig Aliases
- CVE-2025-58049 — XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
- CVE-2025-59955 — Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
- CVE-2026-54421 — In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized f
- CVE-2025-14267 — Unintended temporary cached data included in a structure only copy intended to be empty of data
- CVE-2025-68131 — CBORDecoder reuse can leak shareable values across decode calls
- CVE-2024-56353 — In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
- CVE-2026-78658 — IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
- CVE-2026-27892 — FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
- CVE-2025-62483 — Zoom Clients - Improper Removal of Sensitive Information
Recently published
- CVE-2026-86740 — Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
- CVE-2026-82069 — Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router
- CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
- CVE-2026-78658 — IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
- CVE-2026-85094 — The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privilege
- CVE-2024-5300 — AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
- CVE-2026-15811 — Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes
- CVE-2026-16104 — Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins
- CVE-2026-45737 — Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
- CVE-2026-54421 — In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized f
- CVE-2026-46657 — Bludit's persistent authentication tokens not revoked upon account disablement
- CVE-2026-45046 — Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content
- CVE-2026-27892 — FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/Download
- CVE-2026-42186 — OpenBao's Namespace Deletion May Not Delete Data Properly
- CVE-2026-42880 — ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
- CVE-2024-43384 — Phoenix Contact: Improper removal of sensitive information in MGUARD products
- CVE-2026-43528 — OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig Aliases
- CVE-2026-43824 — In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
- CVE-2026-39937 — Global vanishing does not completely remove user email
- CVE-2026-34214 — Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON
More specific weaknesses
- CWE-1258 — Exposure of Sensitive System Information Due to Uncleared Debug Information