Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39879

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Due to a missing sanitization call in afsql_dd_run_query, syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

A flaw was found in syslog-ng. An attacker on an adjacent network can exploit a missing sanitization call in the afsql_dd_run_query function, leading to a SQL injection vulnerability. This vulnerability, when the SQL driver is manually configured, can result in a denial of service and allow for limited data manipulation from an untrusted source.

Отчет

This is an Important flaw in syslog-ng, as an attacker on an adjacent network could perform SQL injection. This vulnerability is not present in default configurations and requires the SQL driver to be manually configured, limiting its immediate impact on typical Red Hat deployments. Successful exploitation could lead to denial of service and limited data manipulation.

Меры по смягчению последствий

To mitigate this vulnerability, avoid manually configuring and enabling the syslog-ng SQL driver if it is not essential for your environment. If the SQL driver is required, restrict network access to the syslog-ng instance to trusted networks only, for example, by configuring firewall rules to limit connections to the syslog-ng port. Note that changes to network configurations or syslog-ng service settings may require a service reload or restart to take effect, which could temporarily interrupt logging services.

Дополнительная информация

Статус:

Important
Дефект:
CWE-150
https://bugzilla.redhat.com/show_bug.cgi?id=2502916syslog-ng: syslog-ng: SQL Injection vulnerability leading to denial of service and data manipulation

EPSS

Процентиль: 7%
0.00172
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
17 дней назад

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

CVSS3: 7.1
nvd
17 дней назад

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

msrc
16 дней назад

SQL injection in syslog-ng SQL destionation driver

CVSS3: 7.1
debian
17 дней назад

Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...

EPSS

Процентиль: 7%
0.00172
Низкий

7.1 High

CVSS3

Уязвимость CVE-2026-39879