Heap Corruption Vulnerability in GoAccess Web Log Analyzer
CVE-2026-54715

7.1HIGH

Key Information:

Vendor

Allinurl

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-54715?

GoAccess, a real-time web log analyzer, is affected by a vulnerability in version 1.10.2 that arises from improper handling of browser tokens. The 'parse_browser' function inaccurately processes the User-Agent string, potentially leading to memory corruption. An attacker can exploit this flaw by crafting a specific User-Agent input, which may cause the application to write bytes beyond its designated heap memory allocation, resulting in unexpected behavior, including crashes. This vulnerability has been addressed in version 1.11, emphasizing the importance of updating to maintain security.

Affected Version(s)

goaccess >= 1.10.2, < 1.11

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.