CWE-117
CWE-117 · 6 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-117, highest CVSS first.
- MEDIUM 5.3CVE-2026-85290public PoC
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing CRLF chara…
- MEDIUM 5.3CVE-2026-84501
An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvi…
zookeeper
- MEDIUM 5.3CVE-2026-84439
When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the username. Because the aud…
zookeeper
- MEDIUM 4.3CVE-2026-6327
IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
concert · linux kernel
- UNSCOREDCVE-2026-93421public PoC
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/serve…
- UNSCOREDCVE-2026-86522public PoC
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters. AshAuthentication.St…