SQL injection in syslog-ng - CVE-2026-39879
Published: June 16, 2026
syslog-ng
Detailed vulnerability description
The vulnerability allows a remote attacker to perform SQL injection.
The vulnerability exists due to improper neutralization of escape, meta, or control sequences in afsql_dd_run_query when processing data from an untrusted source in the SQL destination driver. A remote attacker can supply crafted input to perform SQL injection.
Only deployments with the SQL destination driver manually configured are vulnerable.