Cyber Resilience

CWE · MITRE source

CWE-209Generation of Error Message Containing Sensitive Information

Abstraction: Base · CVEs in our corpus: 592

The product generates an error message that includes sensitive information about its environment, users, or associated data.

Last updated: 22 August 2026 00:25 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 3 mapping(s) from 1 framework(s): CAPEC 3 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A10:2025 Mishandling of Exceptional Conditions.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SI-11 Error Handling
  • SI-15 Information Output Filtering
  • SI-17 Fail-safe Procedures
  • AU-13 Monitoring for Information Disclosure
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V16.5.1

NIST 800-53 r5 controls that address this weakness (6)AI-assisted

Control Title Family Why it addresses this CWE
SI-11Error HandlingSIExplicitly requires error messages to avoid including sensitive or exploitable details while still supporting corrective action.
SI-15Information Output FilteringSIValidation ensures error messages contain only expected, non-sensitive content and blocks leakage via verbose errors.
SI-17Fail-safe ProceduresSIFail-safe procedures can be defined to suppress or sanitize error output, reducing generation of messages that contain sensitive information.
AU-13Monitoring for Information DisclosureAUDetects error messages that leak sensitive information as evidence of disclosure.
IA-6Authentication FeedbackIAThe control directly mitigates generation of error messages containing sensitive authentication details by requiring obscured feedback instead of verbose responses.
SC-30Concealment and MisdirectionSCMisdirection allows generation of misleading error messages that withhold or falsify sensitive details.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-62168 9.610.00.62872025-10-17
CVE-2024-29059 KEV 8.57.50.98622024-03-23
CVE-2013-7331 KEV 7.86.50.58022014-02-26
CVE-2018-11325 7.89.80.03272018-05-22
CVE-2026-22778 7.89.80.03722026-02-02
CVE-2019-7612 7.79.80.02412019-03-25
CVE-2021-22145 7.76.50.76252021-07-21
CVE-2017-7945 7.69.80.01842017-04-29
CVE-2017-7551 7.69.80.01422017-08-16
CVE-2018-14925 7.69.80.01542018-08-03
CVE-2019-7644 7.69.80.01662019-04-11
CVE-2021-42777 7.59.80.00972022-10-29
CVE-2023-40763 7.59.80.00892023-08-28
CVE-2025-47813 KEV 7.54.30.59402025-07-10
CVE-2023-40757 7.49.80.00752023-08-28
CVE-2023-40758 7.49.80.00752023-08-28
CVE-2023-40759 7.49.80.00752023-08-28
CVE-2023-40760 7.49.80.00752023-08-28
CVE-2023-40761 7.49.80.00752023-08-28
CVE-2023-40762 7.49.80.00752023-08-28
CVE-2023-40764 7.49.80.00752023-08-28
CVE-2023-40765 7.49.80.00752023-08-28
CVE-2023-40766 7.49.80.00752023-08-28
CVE-2023-40767 7.49.80.00752023-08-28
CVE-2024-28285 7.39.80.00502024-05-14