Cyber Posture

CWE · MITRE source

CWE-209Generation of Error Message Containing Sensitive Information

Abstraction: Base · CVEs in our corpus: 544

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (6)AI

Control Title Family Why it addresses this CWE
SI-11Error HandlingSIExplicitly requires error messages to avoid including sensitive or exploitable details while still supporting corrective action.
SI-15Information Output FilteringSIValidation ensures error messages contain only expected, non-sensitive content and blocks leakage via verbose errors.
SI-17Fail-safe ProceduresSIFail-safe procedures can be defined to suppress or sanitize error output, reducing generation of messages that contain sensitive information.
AU-13Monitoring for Information DisclosureAUDetects error messages that leak sensitive information as evidence of disclosure.
IA-6Authentication FeedbackIAThe control directly mitigates generation of error messages containing sensitive authentication details by requiring obscured feedback instead of verbose responses.
SC-30Concealment and MisdirectionSCMisdirection allows generation of misleading error messages that withhold or falsify sensitive details.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-29059 KEV9.17.50.93722024-03-23
CVE-2013-7331 KEV8.26.50.81812014-02-26
CVE-2023-275876.67.40.85802023-03-13
CVE-2024-454406.35.30.87542024-08-29
CVE-2024-217335.55.30.73432024-01-19
CVE-2021-221455.46.50.67932021-07-21
CVE-2010-33325.00.00.83602010-09-22
CVE-2025-47813 KEV4.44.30.25012025-07-10
CVE-2024-397194.27.50.44512024-10-31
CVE-2022-292663.77.50.35842022-04-20
CVE-2021-303572.95.30.29982021-06-08
CVE-2021-311592.55.30.24292021-06-16
CVE-2018-179612.48.60.11332018-10-15
CVE-2020-154782.47.50.14712020-07-01
CVE-2017-79452.09.80.00442017-04-29
CVE-2017-75512.09.80.00262017-08-16
CVE-2018-113252.09.80.00032018-05-22
CVE-2018-149252.09.80.00412018-08-03
CVE-2019-76122.09.80.00452019-03-25
CVE-2019-76442.09.80.00522019-04-11
CVE-2022-06602.07.50.07502022-02-18
CVE-2021-427772.09.80.00452022-10-29
CVE-2023-407572.09.80.00102023-08-28
CVE-2023-407582.09.80.00102023-08-28
CVE-2023-407592.09.80.00102023-08-28