CWE-215Base

Insertion of Sensitive Information Into Debugging Code

Draft in the CWE catalog · 19 CVEs mapped

19
CVEs mapped
6.8
Median CVSS
What it is

The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

Recent examples
4.3cvss
CVE-2026-21759

CVE-2026-21759 - MEDIUM Severity Vulnerability

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.

MEDIUMno explanation yet
0%
epss
9.3cvss
CVE-2026-74799

CVE-2026-74799 - CRITICAL Severity Vulnerability

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.

CRITICALno explanation yet
0%
epss
7.0cvss
CVE-2026-44934

Exposed tokens in SUSE Rancher AI Agent logs

A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-215
Abstraction
Base
Structure
Simple
Status
Draft