Input validation error in rsyslog - #VU139164
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the imptcp input module regex framing implementation when processing crafted input over a TCP connection to an imptcp listener configured with framing.delimiter.regex. A remote attacker can send crafted input to cause a denial of service.
The issue affects only deployments that explicitly load the optional imptcp module and configure an imptcp listener with the non-default framing.delimiter.regex setting. Default imptcp framing modes and the imtcp module are not affected.