Infinite loop in Graylog Forwarder and Graylog - #VU150169
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a loop with an unreachable exit condition in the IPFIX input parser when processing a specially crafted IPFIX datagram. A remote attacker can send a specially crafted IPFIX datagram to cause a denial of service.
Restarting the node does not clear the condition, and message processing on unrelated inputs can also be blocked.
Affected software
Graylog
Remediation
Graylog - addressed in versions 7.0.13, 7.1.9