Common Weakness Enumeration

CWE-532

Allowed

Insertion of Sensitive Information into Log File

Abstraction: Base · Status: Incomplete

The product writes sensitive information to a log file.

1952 vulnerabilities reference this CWE, most recent first.

GHSA-WG52-V6X4-GHP3

Vulnerability from github – Published: 2022-05-24 16:53 – Updated: 2024-04-04 01:40
VLAI
Details

OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2019-13515"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-08-15T19:15:00Z",
    "severity": "MODERATE"
  },
  "details": "OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.",
  "id": "GHSA-wg52-v6x4-ghp3",
  "modified": "2024-04-04T01:40:38Z",
  "published": "2022-05-24T16:53:42Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13515"
    },
    {
      "type": "WEB",
      "url": "https://www.us-cert.gov/ics/advisories/icsa-19-225-02"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WG5X-3G47-V38R

Vulnerability from github – Published: 2026-05-19 15:40 – Updated: 2026-06-09 13:12
VLAI
Summary
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
Details

When chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server.

Recommendation

  • Update to the fixed version of the chaincode runtime.
  • Redact or remove existing logs that contain the TLS private key password.
  • Change the TLS private key password.

Mitigation

Impacted deployments can mitigate the vulnerability by restricting the logging level to WARNING or higher so that INFO level logs are not written.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 2.5.9"
      },
      "package": {
        "ecosystem": "Maven",
        "name": "org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.3.1"
            },
            {
              "fixed": "2.5.10"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-45581"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-19T15:40:13Z",
    "nvd_published_at": "2026-06-08T17:16:44Z",
    "severity": "MODERATE"
  },
  "details": "When chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server.\n\n### Recommendation\n\n- Update to the fixed version of the chaincode runtime.\n- Redact or remove existing logs that contain the TLS private key password.\n- Change the TLS private key password.\n\n### Mitigation\n\nImpacted deployments can mitigate the vulnerability by restricting the logging level to WARNING or higher so that INFO level logs are not written.",
  "id": "GHSA-wg5x-3g47-v38r",
  "modified": "2026-06-09T13:12:11Z",
  "published": "2026-05-19T15:40:13Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/hyperledger/fabric-chaincode-java/security/advisories/GHSA-wg5x-3g47-v38r"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45581"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/hyperledger/fabric-chaincode-java"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode"
}

GHSA-WGPQ-P2HM-56V9

Vulnerability from github – Published: 2024-02-01 15:30 – Updated: 2024-05-23 13:55
VLAI
Summary
glance-store logs s3 access keys
Details

A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "glance-store"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "4.6.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-1141"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532",
      "CWE-779"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-05T22:32:25Z",
    "nvd_published_at": "2024-02-01T15:15:08Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.",
  "id": "GHSA-wgpq-p2hm-56v9",
  "modified": "2024-05-23T13:55:44Z",
  "published": "2024-02-01T15:30:24Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1141"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openstack/glance_store/commit/d6e531af4821c8466b1e9404f12f89f6216417f2"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2024:2732"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/CVE-2024-1141"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2258836"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/openstack/glance_store"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "glance-store logs s3 access keys"
}

GHSA-WGR7-WRHM-VCMG

Vulnerability from github – Published: 2024-03-22 00:31 – Updated: 2025-03-27 21:31
VLAI
Details

An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-24272"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-03-21T22:15:10Z",
    "severity": "HIGH"
  },
  "details": "An issue in iTop DualSafe Password Manager \u0026 Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.",
  "id": "GHSA-wgr7-wrhm-vcmg",
  "modified": "2025-03-27T21:31:03Z",
  "published": "2024-03-22T00:31:14Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24272"
    },
    {
      "type": "WEB",
      "url": "https://research.hisolutions.com/2024/03/cve-2024-24272-dualsafe-password-manager-leaks-credentials"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WHP8-C256-P9F6

Vulnerability from github – Published: 2025-06-12 18:31 – Updated: 2025-06-12 18:31
VLAI
Details

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-36573"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-06-12T16:15:23Z",
    "severity": "HIGH"
  },
  "details": "Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.",
  "id": "GHSA-whp8-c256-p9f6",
  "modified": "2025-06-12T18:31:48Z",
  "published": "2025-06-12T18:31:48Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36573"
    },
    {
      "type": "WEB",
      "url": "https://www.dell.com/support/kbdoc/en-us/000323183/dsa-2025-218"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WHPH-446H-6M9V

Vulnerability from github – Published: 2022-04-16 00:00 – Updated: 2023-08-03 19:30
VLAI
Summary
Azure SDK for .NET Information Disclosure Vulnerability.
Details

Azure SDK for .NET Information Disclosure Vulnerability via undisclosed methods relating to lack of sanitization of exception messages.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "NuGet",
        "name": "Microsoft.Rest.ClientRuntime"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.3.24"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2022-26907"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-07T21:30:44Z",
    "nvd_published_at": "2022-04-15T19:15:00Z",
    "severity": "MODERATE"
  },
  "details": "Azure SDK for .NET Information Disclosure Vulnerability via undisclosed methods relating to lack of sanitization of exception messages.",
  "id": "GHSA-whph-446h-6m9v",
  "modified": "2023-08-03T19:30:54Z",
  "published": "2022-04-16T00:00:28Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-26907"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Azure/azure-sdk-for-net/pull/28169"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Azure/azure-sdk-for-net/commit/e67f2a9fc5aa1060bd465d1458c347671268f6f5"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/Azure/azure-sdk-for-net"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Azure/azure-sdk-for-net/blob/a919c48ae294fed084a9679b6f53ac6af3fb4c3a/sdk/mgmtcommon/ClientRuntime/ClientRuntime/Microsoft.Rest.ClientRuntime.csproj#L11"
    },
    {
      "type": "WEB",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26907"
    },
    {
      "type": "WEB",
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-26907"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Azure SDK for .NET Information Disclosure Vulnerability."
}

GHSA-WHVH-7626-25QP

Vulnerability from github – Published: 2023-03-27 06:30 – Updated: 2023-03-27 06:30
VLAI
Details

Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-39043"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-200",
      "CWE-532"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-03-27T04:15:00Z",
    "severity": "LOW"
  },
  "details": "Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.",
  "id": "GHSA-whvh-7626-25qp",
  "modified": "2023-03-27T06:30:22Z",
  "published": "2023-03-27T06:30:22Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-39043"
    },
    {
      "type": "WEB",
      "url": "https://www.twcert.org.tw/tw/cp-132-6922-4a37a-1.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WJ3P-5H3X-C74Q

Vulnerability from github – Published: 2026-03-03 16:44 – Updated: 2026-03-04 18:38
VLAI
Summary
Rancher Backup Operator pod's logs leak S3 tokens
Details

Impact

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

Specifically, the S3 accessKey and secretKey are exposed in the pod's logs under the following logging level conditions:

Variable Exposed Logging Level Condition
accessKey trace: false (default), and debug: false (default)
secretKey trace: true or debug: true

Note: The S3 accessKey is exposed in the logs without requiring any supplementary configuration.

For further information on this attack category, please consult the associated MITRE ATT&CK - Technique - Log Enumeration.

Patches

This vulnerability is addressed by applying redaction to sensitive information that was leaking.

Patched versions of Rancher Backup Operator include: 108.0.1+up9.0.1, 107.1.2+up8.1.2, 106.0.6+up7.0.5, and 105.0.6+up6.0.3.

Workarounds

Users are advised to rotate both S3 accessKey and secretKey once they have upgraded to a fixed version, especially if logs are exported.

Users who cannot update Rancher are advised to refresh the Rancher app Repository, which should provide the ability to update just the Rancher Backup chart alone. This will patch the vulnerabilities without requiring Rancher to be updated. This will not work for Rancher clusters in an air-gap setup.

For air-gapped Rancher clusters, the Rancher version must be updated first, and then after you will find the patched version of the Rancher Backup chart to upgrade. You will also need to sync new images for the release to your image mirror.

Users who cannot update either Rancher or Rancher Backup should ensure that both debug and trace values are both false (default). Users should revert the values to the default until they can update to prevent potential leaks.

References

If you have any questions or comments about this advisory: - Reach out to the SUSE Rancher Security team for security related inquiries. - Open an issue in the Rancher repository. - Verify with our support matrix and product support lifecycle.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/backup-restore-operator"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.0.0"
            },
            {
              "fixed": "9.0.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/backup-restore-operator"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "8.0.0"
            },
            {
              "fixed": "8.1.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/backup-restore-operator"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "7.0.0"
            },
            {
              "fixed": "7.0.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/rancher/backup-restore-operator"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.0.0"
            },
            {
              "fixed": "6.0.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-62879"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-03T16:44:18Z",
    "nvd_published_at": "2026-03-04T16:16:25Z",
    "severity": "MODERATE"
  },
  "details": "### Impact\nA vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both `accessKey` and `secretKey`) into the rancher-backup-operator pod\u0027s logs.\n\nSpecifically, the S3 `accessKey` and `secretKey` are exposed in the pod\u0027s logs under the following logging level conditions:\n\n| Variable Exposed | Logging Level Condition | \n------------------ | ------------------------- |\n| accessKey            | `trace: false` (default), and `debug: false` (default) |\n| secretKey             | `trace: true` or `debug: true`|\n\n**Note:** The S3 `accessKey` is exposed in the logs without requiring any supplementary configuration.\n\nFor further information on this attack category, please consult the associated [MITRE ATT\u0026CK - Technique - Log Enumeration](https://attack.mitre.org/techniques/T1654/).\n\n### Patches\nThis vulnerability is addressed by applying redaction to sensitive information that was leaking.\n\nPatched versions of Rancher Backup Operator include: `108.0.1+up9.0.1`, `107.1.2+up8.1.2`, `106.0.6+up7.0.5`, and `105.0.6+up6.0.3`.\n\n### Workarounds\nUsers are advised to rotate both S3 `accessKey` and `secretKey` once they have upgraded to a fixed version, especially if logs are exported.\n\nUsers who cannot update Rancher are advised to refresh the Rancher app Repository, which should provide the ability to update just the Rancher Backup chart alone. This will patch the vulnerabilities without requiring Rancher to be updated. This will not work for Rancher clusters in an air-gap setup.\n\nFor air-gapped Rancher clusters, the Rancher version must be updated first, and then after you will find the patched version of the Rancher Backup chart to upgrade. You will also need to sync new images for the release to your image mirror.\n\nUsers who cannot update either Rancher or Rancher Backup should ensure that both debug and trace values are both false (default). Users should revert the values to the default until they can update to prevent potential leaks.\n\n### References\nIf you have any questions or comments about this advisory:\n- Reach out to the [SUSE Rancher Security team](https://github.com/rancher/rancher/security/policy) for security related inquiries.\n- Open an issue in the [Rancher](https://github.com/rancher/rancher/issues/new/choose) repository.\n- Verify with our [support matrix](https://www.suse.com/suse-rancher/support-matrix/all-supported-versions/) and [product support lifecycle](https://www.suse.com/lifecycle/).",
  "id": "GHSA-wj3p-5h3x-c74q",
  "modified": "2026-03-04T18:38:37Z",
  "published": "2026-03-03T16:44:18Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/rancher/backup-restore-operator/security/advisories/GHSA-wj3p-5h3x-c74q"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62879"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62879"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/rancher/backup-restore-operator"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Rancher Backup Operator pod\u0027s logs leak S3 tokens"
}

GHSA-WJ75-7J4G-J268

Vulnerability from github – Published: 2023-08-02 18:30 – Updated: 2024-04-04 06:29
VLAI
Details

Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-36494"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-08-02T16:15:10Z",
    "severity": "MODERATE"
  },
  "details": "\nAudit logs on F5OS-A may contain undisclosed sensitive information.\u00a0 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
  "id": "GHSA-wj75-7j4g-j268",
  "modified": "2024-04-04T06:29:50Z",
  "published": "2023-08-02T18:30:26Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36494"
    },
    {
      "type": "WEB",
      "url": "https://my.f5.com/manage/s/article/K000134922"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WJJ6-G7C3-Q75F

Vulnerability from github – Published: 2026-09-22 21:31 – Updated: 2026-09-22 21:31
VLAI
Details

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-95815"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-532"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-22T21:17:34Z",
    "severity": "HIGH"
  },
  "details": "OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged deep links to submit agent requests without local confirmation prompts.",
  "id": "GHSA-wjj6-g7c3-q75f",
  "modified": "2026-09-22T21:31:31Z",
  "published": "2026-09-22T21:31:31Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/security/advisories/GHSA-5j57-84cx-r295"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-95815"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/commit/8361f3704dd5e151ff1325e62ff5de658b6c62e6"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openclaw/openclaw/blob/935c16b5e22fae3c7ff5fdee0b834d5e0077d1f6/apps/ios/Sources/Model/NodeAppModel.swift#L10037-L10038"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/openclaw-ios-before-2026.8.11-credential-exposure-via-deep-link-url-logging"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

Mitigation
Architecture and Design Implementation

Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.

Mitigation
Distribution

Remove debug log files before deploying the application into production.

Mitigation
Operation

Protect log files against unauthorized read/write.

Mitigation
Implementation

Adjust configurations appropriately when software is transitioned from a debug state to production.

CAPEC-215: Fuzzing for application mapping

An attacker sends random, malformed, or otherwise unexpected messages to a target application and observes the application's log or error messages returned. The attacker does not initially know how a target will respond to individual messages but by attempting a large number of message variants they may find a variant that trigger's desired behavior. In this attack, the purpose of the fuzzing is to observe the application's log and error messages, although fuzzing a target can also sometimes cause the target to enter an unstable state, causing a crash.