CWE-779: Logging of Excessive Data
The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.
18 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-36416 — SuiteCRM v4 API Excessive log data DOS
- CVE-2025-8696 — DoS attack against the Stork UI from an unauthenticated user
- CVE-2026-86200 — PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT
- CVE-2024-1141 — Glance-store: glance store access key logged in debug log level
- CVE-2025-53636 — Open OnDemand Shell App closed websocket DoS
- CVE-2026-28718 — Denial of service due to insufficient input validation in authentication logging. The following products are affected: A
- CVE-2026-20210 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2026-20209 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2025-69230 — AIOHTTP Vulnerable to Cookie Parser Warning Storm
Recently published
- CVE-2026-86200 — PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT
- CVE-2026-20210 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2026-20209 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2026-28718 — Denial of service due to insufficient input validation in authentication logging. The following products are affected: A
- CVE-2025-69230 — AIOHTTP Vulnerable to Cookie Parser Warning Storm
- CVE-2025-8696 — DoS attack against the Stork UI from an unauthenticated user
- CVE-2025-53636 — Open OnDemand Shell App closed websocket DoS
- CVE-2024-36416 — SuiteCRM v4 API Excessive log data DOS
- CVE-2024-1141 — Glance-store: glance store access key logged in debug log level