CVE-2026-55841
high
CVSS v3
7.5
CVSS v4 NEW
—
VIR risk
7.5
Description
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.graylog2:graylog2-server | <6.3.12 | 6.3.12 |
| Maven | org.graylog2:graylog2-server | >=7.0.0,<7.0.7 | 7.0.7 |
| Maven | org.graylog2:graylog2-server | >=7.1.0,<7.1.2 | 7.1.2 |
References
- https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f
- https://github.com/Graylog2/graylog2-server/commit/85dc699d6319aea433583dc239077a3a799c8627
- https://github.com/Graylog2/graylog2-server/commit/d5051e604c962ef3d4e5e8e434d0ff4907d2140d
- https://github.com/Graylog2/graylog2-server/commit/dde76d7432c469887d9a95c208083c5f0f73c70d
- https://github.com/Graylog2/graylog2-server/pull/26050
- https://github.com/Graylog2/graylog2-server/pull/26056
- https://github.com/Graylog2/graylog2-server/pull/26057
- https://github.com/Graylog2/graylog2-server/pull/26059
- https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-gqr6-r77p-c2pj
- https://github.com/Graylog2/graylog2-server
CWEs
CWE-138
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.