Heap Corruption Vulnerability in GoAccess Web Log Analyzer
CVE-2026-54715
7.1HIGH
What is CVE-2026-54715?
GoAccess, a real-time web log analyzer, is affected by a vulnerability in version 1.10.2 that arises from improper handling of browser tokens. The 'parse_browser' function inaccurately processes the User-Agent string, potentially leading to memory corruption. An attacker can exploit this flaw by crafting a specific User-Agent input, which may cause the application to write bytes beyond its designated heap memory allocation, resulting in unexpected behavior, including crashes. This vulnerability has been addressed in version 1.11, emphasizing the importance of updating to maintain security.
Affected Version(s)
goaccess >= 1.10.2, < 1.11
