Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-117
Weakness type CWE-117 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 31 | 31 | 0 |
Monthly trend
▂▁▁▁▅▂▇█▁
2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 7 · 2026-07 1 · 2026-08 10 · 2026-09 12 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-17481 | 9.8 | 58.8 | — | IBM Documentation Offline is vulnerable to information disclosure, session forgery and … |
| CVE-2026-84439 | 5.3 | 53.1 | — | Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources |
| CVE-2026-84501 | 5.3 | 53.1 | — | Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticati… |
| CVE-2026-86522 | 6.3 | 52.9 | — | Log injection via an unescaped password reset identity in AshAuthentication |
| CVE-2026-62948 | 9.6 | 45.8 | — | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN… |
| CVE-2026-12616 | 6.9 | 43.4 | — | — |
| CVE-2026-44256 | 5.3 | 39.6 | — | Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username |
| CVE-2026-54511 | 8.6 | 38.9 | — | @logtape/syslog: syslog log injection via unescaped control characters and unvalidated … |
| CVE-2026-45565 | 8.1 | 38.3 | — | Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for se… |
| CVE-2026-9016 | 5.3 | 36.4 | — | Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs vi… |
| CVE-2026-10745 | 7.9 | 34.8 | — | — |
| CVE-2026-5078 | 5.3 | 33.5 | — | morgan vulnerable to Log Forging via unneutralized control characters in :remote-user |
| CVE-2026-87859 | 5.3 | 32.9 | — | morgan vulnerable to Log Injection via unescaped double quote in quoted log fields |
| CVE-2026-93421 | 5.3 | 32.3 | — | Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint |
| CVE-2026-48083 | 6.5 | 28.0 | — | OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF inject… |
| CVE-2026-18148 | 4.3 | 25.7 | — | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-45679 | 6.5 | 20.8 | — | OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages |
| CVE-2026-15603 | 5.3 | 20.1 | — | morgan vulnerable to Log Forging via unescaped Unicode line separators |
| CVE-2026-9736 | 4.3 | 19.2 | — | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-16188 | 5.3 | 18.1 | — | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multipl… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 8 |
| jahlives | 4 |
| morgan | 3 |
| apache | 2 |
| dahlia | 1 |
| eclipse foundation | 1 |
| invoiceplane | 1 |
| mesop-dev | 1 |
| open-reception | 1 |
| open-telemetry | 1 |
| openwrt | 1 |
| qriouslad | 1 |
| red hat | 1 |
| roxy-wi | 1 |
| splunk | 1 |