Improper Authentication in Graylog - CVE-2025-30373
Published: April 7, 2025 / Updated: June 25, 2026
Graylog
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass HTTP input authentication and inject messages.
The vulnerability exists due to improper authentication in HTTP inputs when handling HTTP-based ingestion requests with a missing or incorrect Authorization header. A remote attacker can send a specially crafted request to bypass HTTP input authentication and inject messages.
The server returns an HTTP 401 response even though the message is still ingested.