CWE-532: Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
736 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-22778 — vLLM leaks a heap address when PIL throws an error
- CVE-2025-14437 — Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
- CVE-2026-5128 — A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker
- CVE-2024-34706 — @valtimo/components exposes access token to form.io
- CVE-2024-48852 — Information disclosures
- CVE-2025-7426 — MINOVA TTA Information Disclosure and Credential Exposure
- CVE-2025-54120 — PCL Community Edition exposes login credentials in logs
- CVE-2025-22275 — iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from termina
- CVE-2025-8663 — Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know
- CVE-2025-43888 — Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information in
- CVE-2025-30105 — Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p
- CVE-2025-26332 — TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log
- CVE-2024-47083 — Power Platform Terraform Provider has Improper Masking of Secrets in Logs
- CVE-2026-25813 — PlaciPy Exposes Sensitive Data via Application Logs
- CVE-2026-23493 — Pimcore ENV Variables and Cookie Informations are exposed in http_error_log
- CVE-2025-1053 — Brocade SANnav encryption key is logged in the debug logs
- CVE-2024-29959 — Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save
- CVE-2024-52009 — Git credentials are exposed in atlantis logs
- CVE-2024-42407 — Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature cou
- CVE-2024-0912 — CCURE passwords exposed to administrators
Recently published
- CVE-2026-79966 — CWE-532: Insertion of Sensitive Information into Log File
- CVE-2026-80169 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2025-46808 — Sensitive information is leaked into NeuVector’s manager container logs
- CVE-2026-80124 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78631 — Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging
- CVE-2026-78627 — Improper Credential Protection in Okta Hyperdrive Integration Installer Logging
- CVE-2026-86597 — Sensitive information written to logs by Snowflake drivers
- CVE-2026-86501 — In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
- CVE-2026-80056 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-16689 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-17442 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-19649 — IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
- CVE-2026-85174 — SiYuan before v3.8.2 API Token Exposure via Log File
- CVE-2026-85171 — n8n before 1.123.73 Credential Exposure via Error Logging
- CVE-2026-55221 — Boruta: OAuth credentials exposed in Boruta business logs
- CVE-2026-55785 — free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
- CVE-2026-78174 — WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs
- CVE-2026-81530 — KMS master key exposure via unredacted credential serialization in driver settings string
- CVE-2026-75573 — MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplicate Options Are Supplied
- CVE-2026-81715 — openssl_encrypt before 1.4.9 Credential Exposure via Debug Output