CWE-598Variant

Use of HTTP Request With Sensitive Query String

Draft in the CWE catalog · 81 CVEs mapped

81
CVEs mapped
6.0
Median CVSS
What it is

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Recent examples
5.9cvss
CVE-2026-61614

CVE-2026-61614 - MEDIUM Severity Vulnerability

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP Referer headers sent to third-party origins. Version 3.0.1 fixes the issue.

MEDIUMno explanation yet
0%
epss
5.5cvss
CVE-2026-82181

CVE-2026-82181 - MEDIUM Severity Vulnerability

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.

MEDIUMno explanation yet
0%
epss
9.8cvss
CVE-2026-76179

CVE-2026-76179 - CRITICAL Severity Vulnerability

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersonate an authenticated user and gain unauthorized access to device management functionality.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-598
Abstraction
Variant
Structure
Simple
Status
Draft
References (1)