Infinite loop in Graylog Forwarder and Graylog - #VU150169

 

Infinite loop in Graylog Forwarder and Graylog - #VU150169

Published: September 16, 2026


Vulnerability identifier: #VU150169
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a loop with an unreachable exit condition in the IPFIX input parser when processing a specially crafted IPFIX datagram. A remote attacker can send a specially crafted IPFIX datagram to cause a denial of service.

Restarting the node does not clear the condition, and message processing on unrelated inputs can also be blocked.


Affected software

Graylog Forwarder
Graylog

Remediation

Install security update from vendor's website.

Graylog Forwarder - update to 7.6
Graylog - addressed in versions 7.0.13, 7.1.9

External References

Related Security Bulletins