Cyber Resilience

CWE · MITRE source

CWE-779Logging of Excessive Data

Abstraction: Base · CVEs in our corpus: 20

The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.

While logging is a good practice in general, and very high levels of logging are appropriate for debugging stages of development, too much logging in a production environment might hinder a system administrator's ability to detect anomalous conditions. This can provide cover for an attacker while attempting to penetrate a system, clutter the audit trail for forensic analysis, or make it more difficult to debug problems in a production environment.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AU-7 Audit Record Reduction and Report Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-7 Audit Record Reduction and Report Generation
Detect
Catch it (CSF Detect / Respond)
  • DE.AE-02
  • DE.AE-04
  • DE.AE-06
Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
AU-7Audit Record Reduction and Report GenerationAUAudit record reduction explicitly manages excessive log volumes for review and reporting while preserving original content and ordering, reducing the impact of logging excessive data.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-36072 7.59.80.01012024-06-27
CVE-2024-36416 6.68.60.01952024-06-10
CVE-2022-31004 6.07.50.00962022-06-02
CVE-2024-55628 6.07.50.00692025-01-06
CVE-2025-8696 5.87.50.00442025-09-10
CVE-2026-287185.87.50.00342026-03-06
CVE-2025-51397 4.45.40.00872025-07-21
CVE-2025-69230 4.45.30.00342026-01-06
CVE-2021-25420 4.35.50.00242021-06-11
CVE-2021-25421 4.35.50.00242021-06-11
CVE-2021-25422 4.35.50.00242021-06-11
CVE-2021-25423 4.35.50.00242021-06-11
CVE-2023-23949 4.35.40.00562023-01-26
CVE-2025-53636 4.35.40.00282025-07-11
CVE-2024-1141 4.25.50.00232024-02-01
CVE-2026-20209 4.25.40.00192026-05-14
CVE-2026-20210 4.25.40.00192026-05-14
CVE-2022-22291 4.15.50.00102022-02-11
CVE-2022-25779 3.84.30.00532022-05-04
CVE-2022-39874 3.34.00.00182022-10-07