Improper Authentication in Graylog - CVE-2025-30373

 

Improper Authentication in Graylog - CVE-2025-30373

Published: April 7, 2025 / Updated: June 25, 2026


Vulnerability identifier: #VU135310
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30373
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass HTTP input authentication and inject messages.

The vulnerability exists due to improper authentication in HTTP inputs when handling HTTP-based ingestion requests with a missing or incorrect Authorization header. A remote attacker can send a specially crafted request to bypass HTTP input authentication and inject messages.

The server returns an HTTP 401 response even though the message is still ingested.


Affected software

Graylog

How to mitigate CVE-2025-30373

Install security update from vendor's website.

Graylog - update to 6.1.9

External References

Related Security Bulletins