CWE · MITRE source
CWE-209Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Last updated: 22 August 2026 00:25 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 3 mapping(s) from 1 framework(s): CAPEC 3 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A10:2025 Mishandling of Exceptional Conditions.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (6)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SI-11 | Error Handling | SI | Explicitly requires error messages to avoid including sensitive or exploitable details while still supporting corrective action. |
SI-15 | Information Output Filtering | SI | Validation ensures error messages contain only expected, non-sensitive content and blocks leakage via verbose errors. |
SI-17 | Fail-safe Procedures | SI | Fail-safe procedures can be defined to suppress or sanitize error output, reducing generation of messages that contain sensitive information. |
AU-13 | Monitoring for Information Disclosure | AU | Detects error messages that leak sensitive information as evidence of disclosure. |
IA-6 | Authentication Feedback | IA | The control directly mitigates generation of error messages containing sensitive authentication details by requiring obscured feedback instead of verbose responses. |
SC-30 | Concealment and Misdirection | SC | Misdirection allows generation of misleading error messages that withhold or falsify sensitive details. |
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2025-62168 UPD | 9.6 | 10.0 | 0.6287 | 2025-10-17 |
CVE-2024-29059 KEV UPD | 8.5 | 7.5 | 0.9862 | 2024-03-23 |
CVE-2013-7331 KEV UPD | 7.8 | 6.5 | 0.5802 | 2014-02-26 |
CVE-2018-11325 UPD | 7.8 | 9.8 | 0.0327 | 2018-05-22 |
CVE-2026-22778 UPD | 7.8 | 9.8 | 0.0372 | 2026-02-02 |
CVE-2019-7612 UPD | 7.7 | 9.8 | 0.0241 | 2019-03-25 |
CVE-2021-22145 UPD | 7.7 | 6.5 | 0.7625 | 2021-07-21 |
CVE-2017-7945 UPD | 7.6 | 9.8 | 0.0184 | 2017-04-29 |
CVE-2017-7551 UPD | 7.6 | 9.8 | 0.0142 | 2017-08-16 |
CVE-2018-14925 UPD | 7.6 | 9.8 | 0.0154 | 2018-08-03 |
CVE-2019-7644 UPD | 7.6 | 9.8 | 0.0166 | 2019-04-11 |
CVE-2021-42777 UPD | 7.5 | 9.8 | 0.0097 | 2022-10-29 |
CVE-2023-40763 UPD | 7.5 | 9.8 | 0.0089 | 2023-08-28 |
CVE-2025-47813 KEV UPD | 7.5 | 4.3 | 0.5940 | 2025-07-10 |
CVE-2023-40757 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40758 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40759 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40760 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40761 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40762 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40764 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40765 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40766 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2023-40767 UPD | 7.4 | 9.8 | 0.0075 | 2023-08-28 |
CVE-2024-28285 UPD | 7.3 | 9.8 | 0.0050 | 2024-05-14 |