VulnSea

CWE-117

CVEs classified under CWE-117, newest first.

21 CVEsRSS

CVE-2026-11538Low· 3.7
3d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

SunlitIBM · WebSphere Application ServerEPSS 0.16%via NVD
CVE-2026-86522Medium· 6.3
4d ago

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…

Sunlitteam-alembic · ash_authenticationEPSS 0.53%via NVD
CVE-2026-84439Medium· 5.3
5d ago

When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the us…

When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the us…

Sunlitapache · zookeeperEPSS 0.81%via NVD
CVE-2026-84501Medium· 5.3
5d ago

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n)

An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, Ense…

Sunlitapache · zookeeperEPSS 0.78%via NVD
CVE-2026-16189Medium· 4.8
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

SunlitIBM · WebSphere Application ServerEPSS 0.22%via NVD
CVE-2026-16188Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server's administrative log.

SunlitIBM · WebSphere Application ServerEPSS 0.27%via NVD
CVE-2026-87859Medium· 5.3
1w ago

morgan is an HTTP request logger middleware for Node.js

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan …

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.39%via NVD
CVE-2026-15603Medium· 5.3
1w ago

morgan vulnerable to Log Forging via unescaped Unicode line separators

morgan vulnerable to Log Forging via unescaped Unicode line separators

Sunlitmorgan · morganEPSS 0.24%via GHSA
CVE-2026-14350Medium· 5.3
2w ago

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

SunlitEPSS 0.31%via NVD
CVE-2026-9736Medium· 5.3
2w ago

IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

Sunlitibm · netezza_performance_serverEPSS 0.17%via NVD
CVE-2026-54511High· 8.6
3w ago

LogTape is an unobtrusive logging library

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStructuredDataValue() function in packages/syslog/src/syslog.ts does not neutralize C0 control characters from U+0000 thro…

Twilightlogtape · @logtape/syslogEPSS 0.31%via NVD
GHSA-4ph6-mjv7-3fq6Low
4w ago

netfoil vulnerable to improper handling of untrusted DoH response data

netfoil vulnerable to improper handling of untrusted DoH response data

Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
CVE-2026-44256Medium· 5.3
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic authentication username before credential validation and pass…

Sunlitwazuh · wazuhEPSS 0.31%via NVD
CVE-2026-48083Medium· 6.5
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the messag…

SunlitEPSS 0.35%via NVD
CVE-2026-5078Medium· 5.3
2mo ago

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

Sunlitmorgan · morganEPSS 0.33%via GHSA
GHSA-7856-g3gv-9wq8Low
2mo ago

netfoil: Attacker controlled data written to logs

netfoil: Attacker controlled data written to logs

Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
GHSA-7cx2-g3h9-382pHigh· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Twilightcrawl4ai · crawl4aivia GHSA
CVE-2026-42507Medium· 5.3
3mo ago

net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507)

A flaw was found in the net/textproto package in Golang. When functions in this package return errors, they include their input as part of the error message. An attacker could exploit this by injecting misleading content into these error m…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.37%via CSAF
CVE-2026-24308High· 7.5
6mo ago

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values ar…

Twilightapache · zookeeperEPSS 1.2%via NVD
CVE-2026-1337Medium· 5.4PoC
7mo ago

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j prod…

Twilightneo4j · neo4jEPSS 0.23%via NVD
CVE-2023-6484Medium· 5.3
2y ago

A log injection flaw was found in Keycloak

A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.

SunlitEPSS 1.0%via NVD
CWE-117 vulnerabilities (CVEs) · VulnSea