Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39879

Опубликовано: 20 июл. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Due to a missing sanitization call in afsql_dd_run_query, syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.

Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

EPSS

Процентиль: 7%
0.00172
Низкий

7.1 High

CVSS3

Дефекты

CWE-150

Связанные уязвимости

CVSS3: 7.1
ubuntu
17 дней назад

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

CVSS3: 7.1
redhat
17 дней назад

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

msrc
16 дней назад

SQL injection in syslog-ng SQL destionation driver

CVSS3: 7.1
debian
17 дней назад

Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...

EPSS

Процентиль: 7%
0.00172
Низкий

7.1 High

CVSS3

Дефекты

CWE-150