CWE-209— Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.— MITRE CWE catalog
624 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-209page 13 of 13
- CVE-2026-68886MEDIUMCVSS 5.5EG 5.52026-09-08
Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.
- CVE-2026-69247HIGHCVSS 8.2EG 8.22026-08-03
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientI…
- CVE-2026-69294MEDIUMCVSS 5.5EG 5.52026-09-08
Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
- CVE-2026-69552MEDIUMCVSS 5.7EG 5.72026-09-08
Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.
- CVE-2026-69684MEDIUMCVSS 5.5EG 5.52026-09-08
Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.
- CVE-2026-73409MEDIUMCVSS 5.1EG 5.12026-07-24
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could subm…
- CVE-2026-73555MEDIUMCVSS 5.3EG 5.32026-08-13
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_mes…
- CVE-2026-73844LOWCVSS 3.7EG 3.72026-08-14
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server i…
- CVE-2026-74879HIGHCVSS 7.5EG 7.52026-08-17
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitiv…
- CVE-2026-75760HIGHCVSS 7.1EG 7.12026-08-31
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider c…
- CVE-2026-77076MEDIUMCVSS 6.5EG 6.52026-08-20
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the underlying HTTP client error unchanged inste…
- CVE-2026-77950MEDIUMCVSS 6.3EG 6.32026-09-01
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler …
- CVE-2026-7860LOWCVSS 1.6EG 1.62026-05-19
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. B…
- CVE-2026-78693MEDIUMCVSS 6.9EG 6.92026-08-30
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_handler to redact. In AshGraphql.Errors, ea…
- CVE-2026-79777LOWCVSS 2.7EG 2.72026-08-25
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
- CVE-2026-8173MEDIUMCVSS 5.3EG 5.32026-08-24
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, …
- CVE-2026-82580MEDIUMCVSS 5.3EG 5.32026-08-31
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized ver…
- CVE-2026-82727LOWCVSS 2.3EG 2.32026-08-31
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, cr…
- CVE-2026-82733MEDIUMCVSS 6.3EG 6.32026-09-01
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route ha…
- CVE-2026-82739LOWCVSS 2.1EG 2.12026-09-01
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its confirmation check. Ash.Resource.Validation.Confirm's atomic implement…
- CVE-2026-8861MEDIUMCVSS 5.3EG 5.32026-07-17
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
- CVE-2026-92936MEDIUMCVSS 5.8EG 5.82026-09-17
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval…
- CVE-2026-9583MEDIUMCVSS 4.3EG 4.32026-05-26
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to info…
- CVE-2026-9794MEDIUMCVSS 5.3EG 5.32026-05-28
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying …
Map vulnerabilities like CWE-209 to your infrastructure
EchelonGraph correlates every CVE — across CWE-209 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →