Cyber Resilience

CWE · MITRE source

CWE-215Insertion of Sensitive Information Into Debugging Code

Abstraction: Base · CVEs in our corpus: 19

The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

When debugging, it may be necessary to report detailed information to the programmer. However, if the debugging code is not disabled when the product is operating in a production environment, then this sensitive information may be exposed to attackers.

Last updated: 20 August 2026 13:14 UTC

OWASP Top 10 for Web (2025)

This weakness contributes to A10:2025 Mishandling of Exceptional Conditions.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.DS-10
  • PR.PS-01
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V13.4.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-7569 7.19.60.01742024-08-13
CVE-2026-40173 7.19.40.00512026-04-15
CVE-2019-3781 6.88.80.01332019-03-07
CVE-2018-1191 6.78.80.00932018-03-29
CVE-2026-747996.69.30.00392026-08-17
CVE-2025-27684 5.97.50.00572025-03-05
CVE-2025-34081 5.97.50.00602025-07-01
CVE-2026-2250 5.87.50.00362026-02-11
CVE-2026-33247 5.77.40.00412026-03-25
CVE-2022-0721 5.46.50.01402022-02-23
CVE-2023-51390 5.06.50.00282023-12-21
CVE-2018-1002104 4.75.30.01142020-01-14
CVE-2025-58598 4.76.60.00272025-09-03
CVE-2023-49194 4.55.30.00532024-12-09
CVE-2025-12616 3.33.70.00542025-11-03
CVE-2023-21462 3.24.20.00162023-03-16
CVE-2024-22194 2.32.20.00412024-01-11
CVE-2025-0895 2.22.40.00192025-03-02