Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55841

Опубликовано: 28 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Gray

EPSS

Процентиль: 29%
0.00355
Низкий

7.5 High

CVSS3

Дефекты

CWE-138

Связанные уязвимости

CVSS3: 7.5
debian
18 дней назад

Graylog is a free and open log management platform. Prior to Graylog S ...

CVSS3: 7.5
github
18 дней назад

Fortigate syslog message parser can be exploited to modify or delete fields from the original message

EPSS

Процентиль: 29%
0.00355
Низкий

7.5 High

CVSS3

Дефекты

CWE-138