highCVSS 7.5Vulnerability

CVE-2026-55841

### Impact A security issue has been identified in Graylog affecting the parsing of syslog messages that use a key-value format, such as those generated by Fortigate devices. The vulnerability allows attackers to overwrite individual message fields, or to produce invalid messages which Graylog will discard. This effectively enables log evasion techniques to obscure malicious activity. ### Patches The issue has been fixed in the following Graylog versions: `6.3.12`, `7.0.7`, `7.1.2`. Users should upgrade to one of these versions or above to remediate the vulnerability. Graylog Cloud has already been patched. ### Workarounds There are no feasible workarounds for this issue. Upgrading to a patched version is recommended. To find potentially discarded messages due to parsing errors, customers of Graylog Enterprise or Security can check the Indexing and Processing Failures Index[^1]. ### Credits Thanks to Jose Luis González, from Fundación Sarenet, with additional analysis by Borja Marcos from Sarenet. [^1]: https://go2docs.graylog.org/current/getting_in_log_data/indexer_and_processing_failures.html

Properties

ghsa_id
GHSA-gqr6-r77p-c2pj
summary
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
severity
high
cvss_score
7.5
cve_id
CVE-2026-55841
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
false
ghsa_published
2026-08-28T22:13:00Z
source_url
https://github.com/advisories/GHSA-gqr6-r77p-c2pj
ghsa_updated
2026-08-28T22:13:01Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]maven/org.graylog2:graylog2-server

VULNERABLE_TO (1)

[Software]maven/org.graylog2:graylog2-server

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55841 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal