CWE-117

Medium likelihood

Improper Output Neutralization for Logs

Parent: CWE-116 - Improper Encoding or Escaping of Output

The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.

98 vulnerabilities with CWE-117
CVE-2026-20260 MEDIUM
Log Injection through HTTP Request Paths in Splunk SOAR
CVSS 4.3
CVE-2026-45565 HIGH
Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)
CVSS 8.1
CVE-2026-9016 MEDIUM
Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action
CVSS 5.3
CVE-2026-5078 MEDIUM
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVSS 5.3
CVE-2026-45679 MEDIUM
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
CVSS 6.5
CVE-2026-6494 MEDIUM
Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input
CVSS 5.3
CVE-2026-34478 HIGH
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
CVSS 7.5
CVE-2026-25548 CRITICAL
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
CVE-2026-1337 MEDIUM
Neo4j < 2026.01 - Cross-Site Scripting via Query Log Unicode Character Escaping
CVSS 5.4
CVE-2025-14684 MEDIUM
IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .
CVSS 4.0
CVE-2025-59784 HIGH
2N Access Commander <3.4.1 - Log Pollution
CVSS 7.2
CVE-2025-12755 MEDIUM
IBM MQ Operator 3.2.0-3.8.1 - Log Injection
CVSS 4.0
CVE-2025-11537 MEDIUM
Keycloak Quarkus Server < 26.6.0 - Sensitive Header Exposure in Verbose Log Format
CVSS 5.0
CVE-2025-66577 MEDIUM
cpp-httplib <0.27.0 - Log Poisoning
CVSS 5.3
CVE-2025-20384 MEDIUM
Splunk <10.0.1-9.2.10 - Info Disclosure
CVSS 5.3
CVE-2025-36159 MEDIUM
IBM Concert <2.0.0 - Info Disclosure
CVSS 6.2
CVE-2025-11627 MEDIUM
Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each...
CVSS 6.5
CVE-2025-36081 MEDIUM
IBM Concert Software <2.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-57564 HIGH
CubeAPM nightly-2025-08-01-1 - Code Injection
CVSS 8.2
CVE-2025-58580 MEDIUM
SICK Enterprise Analytics - Log Injection via API Endpoint
CVSS 6.5
CVE-2025-10217 MEDIUM
Asset Suite - Info Disclosure
CVE-2025-59476 MEDIUM
Jenkins < 2.516.3 and < 2.528 - Log Forgery via Line Break Injection
CVSS 5.3
CVE-2025-54813 HIGH
Apache Log4cxx <1.5.0 - Info Disclosure
CVSS 7.5
CVE-2025-54812 MEDIUM
Apache Log4cxx < 1.5.0 - Cross-Site Scripting in HTMLLayout Logger Name
CVSS 5.4
CVE-2025-54389 MEDIUM
Advanced Intrusion Detection Environment < 0.19.2 - Log Tampering via Terminal Escape Sequences
CVSS 6.2
Details
Vulnerabilities 98
Exploit Likelihood Medium