Heap-based buffer overflow in rsyslog - CVE-2026-55556

 

Heap-based buffer overflow in rsyslog - CVE-2026-55556

Published: June 24, 2026


Vulnerability identifier: #VU135091
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55556
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in parse_auth_header() in the imhttp module when processing a crafted HTTP Basic Authorization header. A remote attacker can send a single crafted HTTP request to cause a denial of service.

Only deployments where the optional imhttp module is installed, explicitly loaded, and configured with HTTP Basic Authentication for an endpoint are vulnerable.


Affected software

rsyslog

How to mitigate CVE-2026-55556

Install security update from vendor's website.

rsyslog - update to 8.2604.0

External References

Related Security Bulletins