Log Analytics Platform Vulnerability in Parseable
CVE-2026-32641
7.5HIGH
What is CVE-2026-32641?
The Parseable Log Analytics Platform prior to version 3.0.0 exhibits improper input handling due to its use of unwrap() for parsing the x-amz-firehose-common-attributes header without prior authentication. This vulnerability can be exploited by a remote, unauthenticated adversary supplying non-UTF-8 header data or malformed JSON, potentially causing a Rust panic. Such conditions can lead to service disruptions, including prolonged request handling interruptions or endless container restart loops. This issue has been addressed in version 3.0.0.
Affected Version(s)
parseable < 3.0.0
