CWE-117— Improper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.— MITRE CWE catalog
127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-117page 2 of 3
- CVE-2023-4065MEDIUMCVSS 5.5EG 5.52023-09-27
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of…
- CVE-2020-14332MEDIUMCVSS 5.5EG 5.52020-09-11
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. This flaw allows unauthorized users to read this data. The hi…
- CVE-2019-14858MEDIUMCVSS 5.5EG 5.52019-10-14
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail…
- CVE-2026-1337MEDIUMCVSS 5.4EG 5.42026-02-06
Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j produc…
- CVE-2025-54812MEDIUMCVSS 5.4EG 5.42025-08-22
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name of a logger, an attac…
- CVE-2024-52891MEDIUMCVSS 5.4EG 5.42025-01-07
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.
- CVE-2026-85290MEDIUMCVSS 5.3EG 5.32026-09-25
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without ne…
- CVE-2026-93421MEDIUMCVSS 5.3EG 5.32026-09-23
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report h…
- CVE-2026-11538MEDIUMCVSS 5.3EG 5.32026-09-18
IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.
- CVE-2026-84501MEDIUMCVSS 5.3EG 5.32026-09-16
An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, Ensemb…
- CVE-2026-84439MEDIUMCVSS 5.3EG 5.32026-09-16
When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the user…
- CVE-2026-16188MEDIUMCVSS 5.3EG 5.32026-09-14
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
- CVE-2026-87859MEDIUMCVSS 5.3EG 5.32026-09-11
morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan em…
- CVE-2026-14350MEDIUMCVSS 5.3EG 5.32026-09-04
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
- CVE-2026-15603MEDIUMCVSS 5.3EG 5.32026-08-28
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), a…
- CVE-2026-44256MEDIUMCVSS 5.3EG 5.32026-08-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username before credential validation and passes…
- CVE-2026-9016MEDIUMCVSS 5.3EG 5.32026-06-06
The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, 2.5.0. This is due to the `log_js_errors()` AJAX handler …
- CVE-2026-5078MEDIUMCVSS 5.3EG 5.32026-06-03
Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send…
- CVE-2026-6494MEDIUMCVSS 5.3EG 5.32026-04-17
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being …
- CVE-2025-66577MEDIUMCVSS 5.3EG 5.32025-12-05
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attac…
- CVE-2025-20384MEDIUMCVSS 5.3EG 5.32025-12-03
In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (AN…
- CVE-2025-36081MEDIUMCVSS 5.3EG 5.32025-10-28
IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.
- CVE-2025-59476MEDIUMCVSS 5.3EG 5.32025-09-17
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break…
- CVE-2024-52962MEDIUMCVSS 5.3EG 5.32025-04-08
An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.…
- CVE-2024-12580MEDIUMCVSS 5.3EG 5.32025-03-20
A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not val…
- CVE-2025-25294MEDIUMCVSS 5.3EG 5.32025-03-06
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. In all Envoy Gateway versions prior to 1.2.7 and 1.3.1 a default Envoy Proxy access log configuration is used. This f…
- CVE-2025-23405MEDIUMCVSS 5.3EG 5.32025-02-28
Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attacks (ex log injection).
- CVE-2024-49355MEDIUMCVSS 5.3EG 5.32025-02-20
IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature.
- CVE-2024-56473MEDIUMCVSS 5.3EG 5.32025-02-05
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
- CVE-2024-35150MEDIUMCVSS 5.3EG 5.32025-01-25
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
- CVE-2024-8297MEDIUMCVSS 5.3EG 5.32024-08-29
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the …
- CVE-2024-31845MEDIUMCVSS 5.3EG 5.32024-05-21
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified…
- CVE-2023-28952MEDIUMCVSS 5.3EG 5.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
- CVE-2023-6484MEDIUMCVSS 5.3EG 5.32024-04-25
A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
- CVE-2024-1681MEDIUMCVSS 5.3EG 5.32024-04-19
corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. …
- CVE-2023-7234MEDIUMCVSS 5.3EG 5.32024-01-16
OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.
- CVE-2023-46713MEDIUMCVSS 5.3EG 5.32023-12-13
An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an attacker to forge traffic logs via a crafted URL of the web application.
- CVE-2023-31405MEDIUMCVSS 5.3EG 5.32023-07-11
SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interac…
- CVE-2023-0595MEDIUMCVSS 5.3EG 5.32023-02-24
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoSt…
- CVE-2022-1522MEDIUMCVSS 5.3EG 5.32022-09-06
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Output Neutralization for Logs, which allows an attacker to create false logs that show the password as having been chang…
- CVE-2022-32549MEDIUMCVSS 5.3EG 5.32022-06-22
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
- CVE-2021-43410MEDIUMCVSS 5.3EG 5.32021-12-09
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 …
- CVE-2021-20333MEDIUMCVSS 5.3EG 5.32021-07-23
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior…
- CVE-2020-4072MEDIUMCVSS 5.3EG 5.32020-06-25
In generator-jhipster-kotlin version 1.6.0 log entries are created for invalid password reset attempts. As the email is provided by a user and the api is public this can be used by an attacker to forge log entries. This is vulnerable to ht…
- CVE-2026-9736MEDIUMCVSS 4.3EG 5.32026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
- CVE-2025-11537MEDIUMCVSS 5.0EG 5.02026-02-10
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. …
- CVE-2024-0690MEDIUMCVSS 5.0EG 5.02024-02-06
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the tas…
- CVE-2024-22356MEDIUMCVSS 4.9EG 4.92024-03-26
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. …
- CVE-2023-36924MEDIUMCVSS 4.9EG 4.92023-07-11
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the s…
- CVE-2026-16189MEDIUMCVSS 4.8EG 4.82026-09-14
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.
Map vulnerabilities like CWE-117 to your infrastructure
EchelonGraph correlates every CVE — across CWE-117 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →