# CWE-209: Generation of Error Message Containing Sensitive Information

**Likelihood of exploit:** High · **KEV-linked**

> As of 2026-10-05, CWE-209 (Generation of Error Message Containing Sensitive Information) underlies 4 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 5 tracked threats. MITRE rates its likelihood of exploit as High.

**Last updated:** 2026-10-05

## What is CWE-209?

The product generates an error message that includes sensitive information about its environment, users, or associated data.

CWE-209 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: PHP; Language: Java; Language: Not Language-Specific; Technology: Not Technology-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/209.html) (CWE-209 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality** — Read Application Data. Often this will either reveal sensitive information which may be used to launch another, more focused attack or disclose private information stored in the server. For example, an attempt to exploit a path traversal weakness (CWE-22) might yield the full pathname of the installed application. In turn, this could be used to select the proper number of ".." sequences to navigate to the targeted file. An attack using SQL injection (CWE-89) might not initially succeed, but an error message could…

_Source: MITRE CWE, common consequences._

## How CWE-209 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-209, published between 2024-10-31 and 2026-08-03. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 2 high, 1 medium. The highest EPSS score in the set is 39.2% (CVE-2024-39719), the modelled probability of exploitation in the next 30 days. 5 tracked threats reference CWE-209 directly or through a CVE it covers; the most recent is “GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)” (2026-09-11). Affected products concentrate in Ollama (1), Progress Software (1), Wftpserver (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-209, CISA KEV first, then by CVSS score.

- [CVE-2025-47813](https://intel.threadlinqs.com/cve/CVE-2025-47813) — CISA KEV · CVSS 4.3 medium · EPSS 25.4% · published 2025-07-10
- [CVE-2024-39719](https://intel.threadlinqs.com/cve/CVE-2024-39719) — CVSS 7.5 high · EPSS 39.2% · published 2024-10-31
- [CVE-2026-13182](https://intel.threadlinqs.com/cve/CVE-2026-13182) — CVSS 7.5 high · EPSS 0.3% · published 2026-07-22
- [CVE-2026-69247](https://intel.threadlinqs.com/cve/CVE-2026-69247) — published 2026-08-03

## Affected vendors

- [Ollama](https://intel.threadlinqs.com/vendors/ollama) — 1 CVE
- **Progress Software** — 1 CVE
- **Wftpserver** — 1 CVE
- **pyca** — 1 CVE

## Threat activity

5 tracked threats cite CWE-209:

- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2442) — CRITICAL · 2026-09-11
- [Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE (CVE-2026-13181–13184)](https://intel.threadlinqs.com/threat/TL-2026-2369) — HIGH · 2026-09-07
- [Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple)](https://intel.threadlinqs.com/threat/TL-2026-1611) — MEDIUM · 2026-07-22
- [GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing, Local Secret Disclosure, and Path Traversal (CVE Pending)](https://intel.threadlinqs.com/threat/TL-2026-1179) — HIGH · 2026-07-10
- [Wing FTP Server RCE Exploit Chain — Lua Code Injection via NULL Byte (CVE-2025-47812 CVSS 10.0 + CVE-2025-47813)](https://intel.threadlinqs.com/threat/TL-2026-0241) — CRITICAL · 2026-03-17

## Mitigations

- **Implementation**: Ensure that error messages only contain minimal details that are useful to the intended audience and no one else. The messages need to strike the balance between being too cryptic (which can confuse users) or being too detailed (which may reveal more than intended). The messages should not reveal the methods that were used to determine the error. Attackers can use detailed information to refine or optimize their original attack, thereby increasing their chances of success. If errors must be captured in some detail, record them in log messages, but consider what could occur if the log messages can be viewed by attackers. Highly sensitive information such as passwords should never be saved to…
- **Implementation**: Handle exceptions internally and do not display errors containing potentially sensitive information to a user.
- **Implementation / Attack Surface Reduction**: Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.
- **Implementation, Build and Compilation / Compilation or Build Hardening**: Debugging information should not make its way into a production release.
- **Implementation, Build and Compilation / Environment Hardening**: Debugging information should not make its way into a production release.
- **System Configuration**: Where available, configure the environment to use less verbose error messages. For example, in PHP, disable the display_errors setting during configuration, or at runtime using the error_reporting() function.
- **System Configuration**: Create default error pages or messages that do not leak any information.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Manual Analysis** (effectiveness: High): This weakness generally requires domain-specific interpretation using manual analysis. However, the number of potential error conditions may be too large to cover completely within limited time constraints.
- **Automated Analysis** (effectiveness: Moderate): Automated methods may be able to detect certain idioms automatically, such as exposed stack traces or pathnames, but violation of business rules or privacy requirements is not typically feasible.
- **Automated Dynamic Analysis** (effectiveness: Moderate): This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, and fault injection. The software's operation may slow down, but it should not become unstable, crash, or generate incorrect results. Error conditions may be triggered with a stress-test by calling the software simultaneously from a large number of threads or processes, and look for evidence of any…
- **Manual Dynamic Analysis**: Identify error conditions that are not likely to occur during normal usage and trigger them. For example, run the program under low memory conditions, run with insufficient privileges or permissions, interrupt a transaction before it is completed, or disable connectivity to basic network services such as DNS. Monitor the software for any unexpected behavior. If you trigger an unhandled exception or similar error that was discovered and handled by the application's environment, it may still…
- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-200 Exposure of Sensitive Information to an Unauthorized Actor](https://intel.threadlinqs.com/cwe/CWE-200)
- [CWE-755](https://cwe.mitre.org/data/definitions/755.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-209
Source definition: https://cwe.mitre.org/data/definitions/209.html
Detection rules and IOCs for threats exploiting CWE-209 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
