CWE-209— Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.— MITRE CWE catalog
583 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-209page 11 of 12
- CVE-2025-54791MEDIUMCVSS 5.3EG 5.32025-08-13
OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can …
- CVE-2025-55250LOWCVSS 5.3EG 1.82026-01-19
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.
- CVE-2025-55676MEDIUMCVSS 5.5EG 5.52025-10-14
Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.
- CVE-2025-5731MEDIUMCVSS 5.5EG 5.52025-06-26
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a command is not found.
- CVE-2025-59016MEDIUMCVSS 4.3EG 4.32025-09-09
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed…
- CVE-2025-59177MEDIUMCVSS 6.8EG 6.82026-07-27
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.
- CVE-2025-59853LOWCVSS 3.1EG 3.12026-05-06
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to gain insights into the application's internal structure, code logic…
- CVE-2025-59872CRITICALCVSS 9.8EG 9.82026-06-17
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows…
- CVE-2025-61959MEDIUMCVSS 5.3EG 5.32025-10-29
Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insec…
- CVE-2025-62168HIGHCVSS 7.5EG 8.42025-10-17
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protect…
- CVE-2025-62397MEDIUMCVSS 5.3EG 5.32025-10-23
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
- CVE-2025-62840LOWCVSS 3.3EG 3.32026-01-02
A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data.…
- CVE-2025-64749MEDIUMCVSS 4.3EG 4.32025-11-13
Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST API in versions of Directus prior to version 11.13.0. The `/items/{collection}` API…
- CVE-2025-65995MEDIUMCVSS 6.5EG 6.52026-02-21
When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to auth…
- CVE-2025-66549LOWCVSS 2.7EG 2.72025-12-05
Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for admi…
- CVE-2025-66594MEDIUMCVSS 5.3EG 5.32026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed on the error page. This information could be exploited by an attacker for other attacks. The affected products and …
- CVE-2025-68110CRITICALCVSS 9.9EG 9.92025-12-17
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, username, and password. Version 6.5.3 fixes the issue.
- CVE-2025-69208MEDIUMCVSS 5.3EG 5.32026-02-23
free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerability with Information Exposure. All depl…
- CVE-2025-69253MEDIUMCVSS 5.3EG 5.32026-02-24
free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of the User Data Repository are affected by Improper Error Handling with Information Exposure. The NEF component reliably le…
- CVE-2025-71282HIGHCVSS 7.5EG 7.52026-04-01
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure.
- CVE-2025-8548LOWCVSS 3.7EG 3.72025-08-05
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function sendEmailCode of the file src/main/java/co/yiiu/pybbs/controller/api/SettingsApiController.java of the component Registered…
- CVE-2025-8852MEDIUMCVSS 4.3EG 4.32025-08-11
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It i…
- CVE-2025-9005LOWCVSS 3.7EG 3.72025-08-15
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The compl…
- CVE-2025-9122MEDIUMCVSS 5.3EG 5.32025-12-15
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
- CVE-2025-9229MEDIUMCVSS 5.3EG 5.32025-08-20
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.
- CVE-2025-9977MEDIUMCVSS 5.3EG 5.32025-11-18
Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an unauthenticated attacker to perform DoS attacks. SQL injection attacks might also be feas…
- CVE-2026-1175MEDIUMCVSS 7.5EG 5.32026-01-19
A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql of the component GraphQL Directive Handler. Such manipulation leads to information exposure through error message. The…
- CVE-2026-1248MEDIUMCVSS 4.3EG 4.32026-05-27
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
- CVE-2026-1262MEDIUMCVSS 4.3EG 4.32026-03-25
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
- CVE-2026-13182HIGHCVSS 7.5EG 7.52026-07-22
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attacke…
- CVE-2026-20838MEDIUMCVSS 5.5EG 5.52026-01-13
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
- CVE-2026-21783MEDIUMCVSS 4.3EG 4.32026-03-24
HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, e…
- CVE-2026-22052MEDIUMCVSS 4.3EG 4.32026-03-05
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack …
- CVE-2026-22646MEDIUMCVSS 7.5EG 4.32026-01-15
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions…
- CVE-2026-22778CRITICALCVSS 9.8EG 9.82026-02-02
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap …
- CVE-2026-23598MEDIUMCVSS 6.5EG 6.52026-02-17
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such…
- CVE-2026-24130MEDIUMCVSS 5.3EG 5.32026-01-22
Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the lo…
- CVE-2026-24511MEDIUMCVSS 4.4EG 4.42026-04-08
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could p…
- CVE-2026-2484MEDIUMCVSS 4.3EG 4.32026-03-25
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information exposure vulnerability caused by overly verbose error messages
- CVE-2026-27004MEDIUMCVSS 5.5EG 5.52026-02-20
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tools (`sessions_list`, `sessions_history`, `sessions_send`) allowed broader session targeting than some operators intended…
- CVE-2026-2752MEDIUMCVSS 5.3EG 5.32026-03-06
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error…
- CVE-2026-27643MEDIUMCVSS 5.3EG 5.32026-02-24
free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the NEF component reliably leaks internal parsing error details (e.g.…
- CVE-2026-28675MEDIUMCVSS 5.3EG 5.32026-03-06
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints returned raw exception strings to clients. Additionally, login token material was exposed …
- CVE-2026-28786MEDIUMCVSS 4.3EG 4.32026-03-27
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech-to-text transcription endpoint allows any authenticated non-admin user t…
- CVE-2026-29110MEDIUMCVSS 5.3EG 5.32026-03-06
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information about the files stored inside a vault at …
- CVE-2026-29146HIGHCVSS 7.5EG 7.52026-04-09
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 throu…
- CVE-2026-30835MEDIUMCVSS 5.3EG 5.32026-03-06
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.7 and 9.5.0-alpha.6, malformed $regex query parameter (e.g. [abc) causes the database to return a structured err…
- CVE-2026-3259HIGHCVSS 7.1EG 7.12026-04-23
A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism in Google BigQuery on Google Cloud Platform allows an authenticated user to potentially disclose sensitive data using a…
- CVE-2026-33065MEDIUMCVSS 5.3EG 5.32026-03-20
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handlin…
- CVE-2026-33192MEDIUMCVSS 5.3EG 5.32026-03-20
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handlin…
Map vulnerabilities like CWE-209 to your infrastructure
EchelonGraph correlates every CVE — across CWE-209 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →