CWE Database
/

CWE-598

Back to CWE list

CWE-598

Use of HTTP Request With Sensitive Query String

Variant
Draft

Description

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Common Consequences

Scope

Confidentiality

Impact

Read Application Data

Potential Mitigations

Implementation

When sending sensitive information, only include it in the request body or request headers instead of the query string. This may require avoiding use of GET requests.

CVE-2025-1738

Security camera includes a password in its query string

CVE-2025-31954

ML/NLP-based automation product calls a GET method with sensitive information in the query string.

CVE-2024-31842

Web-based communication product includes an access token in the query string of a GET request

CVE-2022-23546

A discussion platform leaks private information in GET requests.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now