← Voltar à pesquisa de CVEs

CVE-2026-39879

syslog-ng

Descrição

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

CVSS 7.1EPSS 0.172%Risco 0.72
Ver fonte
Publicação
2026-07-20 17:17:07
Versões afetadas
<4.12
Tipo
Software crítico
Última alteração
2026-07-23 16:04:11
Vetor
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H