CWE-117: Improper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
107 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-25548 — InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
- CVE-2024-47083 — Power Platform Terraform Provider has Improper Masking of Secrets in Logs
- CVE-2024-29022 — Session Hijacking via XSS attack in header and session grid in Xibo CMS
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
- CVE-2026-81696 — openssl_encrypt before 1.4.9 Terminal Injection via info Command
- CVE-2026-81695 — openssl_encrypt before 1.4.9 Terminal Injection via key_id
- CVE-2026-81694 — verify-usb before 1.4.9 Output Injection via Unsanitized Filenames
- CVE-2026-74885 — openssl_encrypt before 1.4.0 Logging Bug and Race Condition
- CVE-2024-9606 — Improper Output Neutralization for Logs in berriai/litellm
- CVE-2026-17481 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2024-32474 — Sentry's superuser cleartext password leaked in logs
- CVE-2026-54511 — @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
- CVE-2025-59784 — Log Pollution - Control Characters Not Escaped
- CVE-2025-27111 — Escape Sequence Injection vulnerability in Rack lead to Possible Log Injection
- CVE-2025-23405 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Improper Output Neutralization For Logs
- CVE-2024-13949 — Log Forging
- CVE-2026-45565 — Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)
- CVE-2026-10745 — Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows
- CVE-2025-58580 — Injection via log file
- CVE-2025-54813 — Apache Log4cxx: Improper escaping with JSONLayout
Recently published
- CVE-2026-14350 — Vulnerabilities exists in IBM Cloud Pak for Data System
- CVE-2026-9736 — Vulnerabilities exists in IBM Netezza Software
- CVE-2026-15603 — morgan vulnerable to Log Forging via unescaped Unicode line separators
- CVE-2026-81696 — openssl_encrypt before 1.4.9 Terminal Injection via info Command
- CVE-2026-81695 — openssl_encrypt before 1.4.9 Terminal Injection via key_id
- CVE-2026-81694 — verify-usb before 1.4.9 Output Injection via Unsanitized Filenames
- CVE-2026-54511 — @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
- CVE-2026-44256 — Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username
- CVE-2026-74885 — openssl_encrypt before 1.4.0 Logging Bug and Race Condition
- CVE-2026-17481 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2026-18148 — IBM i is Affected By Multiple Vulnerabilities in Navigator for i
- CVE-2026-48083 — OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
- CVE-2026-10745 — Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows
- CVE-2026-20260 — Log Injection through HTTP Request Paths in Splunk SOAR
- CVE-2026-45565 — Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)
- CVE-2026-9016 — Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs via log_js_errors AJAX Action
- CVE-2026-5078 — morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
- CVE-2026-45679 — OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
- CVE-2026-6494 — Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input