CWE-598: Use of HTTP Request With Sensitive Query String
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
81 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2025-26473 — Outback Power Mojave Inverter Use of GET Request Method With Sensitive Query Strings
- CVE-2026-23846 — Tugtainer vulnerable to Password Exposure via URL Query Parameter
- CVE-2026-76179 — Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
- CVE-2026-74880 — openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
- CVE-2025-41772 — wwwupdate.cgi Session token in URL
- CVE-2026-58656 — Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter
- CVE-2026-26196 — Gogs: Access tokens get exposed through URL params in API requests
- CVE-2025-54542 — Sending Password in GET Request
- CVE-2026-62386 — Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
- CVE-2026-54652 — Frigate viewer can read logs exposing admin and camera credentials
- CVE-2025-36371 — IBM i Information Disclosure
- CVE-2026-44883 — Portainer: JWT accepted in URL query leaks tokens to logs and referers
- CVE-2026-25118 — immich-server: Insecure Transmission of Authentication Credentials via Password Parameter in HTTP Request Query String When Accessing Shared Albums
- CVE-2026-15322 — Multiple Vulnerabilities in IBM Engineering AI hub.
- CVE-2025-2356 — BlackVue App API deviceDelete get request method with sensitive query strings
- CVE-2025-0730 — TP-Link TL-SG108E HTTP GET Request usr_account_set.cgi get request method with sensitive query strings
- CVE-2026-9592 — Sensitive Information Disclosure in HTTP header
- CVE-2026-63408 — Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
- CVE-2026-34020 — Apache OpenMeetings: Login Credentials Passed via GET Query Parameters
Recently published
- CVE-2026-61614 — SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history
- CVE-2026-82181 — Le-yan|Medical Practice Management System - Sensitive Data in URL
- CVE-2026-76179 — Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
- CVE-2026-63408 — Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
- CVE-2026-74880 — openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
- CVE-2026-66832 — Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings
- CVE-2026-14838 — Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Digital Human Resources
- CVE-2026-47768 — nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
- CVE-2026-16207 — django-tastypie authentication.py ApiKeyAuthentication get request method with sensitive query strings
- CVE-2026-15322 — Multiple Vulnerabilities in IBM Engineering AI hub.
- CVE-2026-9592 — Sensitive Information Disclosure in HTTP header
- CVE-2026-62386 — Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
- CVE-2026-54652 — Frigate viewer can read logs exposing admin and camera credentials
- CVE-2026-58656 — Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter
- CVE-2026-10078 — Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url querystring
- CVE-2026-44883 — Portainer: JWT accepted in URL query leaks tokens to logs and referers
- CVE-2026-2237 — A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager
- CVE-2025-62317 — HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters.
- CVE-2026-43875 — WWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Takeover
- CVE-2026-34020 — Apache OpenMeetings: Login Credentials Passed via GET Query Parameters