Heap Buffer Vulnerability in Rsyslog's imhttp Module Impacts Log Processing
CVE-2026-55556

8.2HIGH

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-55556?

The vulnerability in Rsyslog's imhttp module, affecting versions 8.2110.0 through 8.2604.0, arises from the parse_auth_header function, which allocates a zero-byte heap buffer due to an oversized HTTP Basic Authorization value. This flaw can be exploited by an unauthenticated remote attacker to send an oversized encoded credential, resulting in potential memory corruption. Although a process crash can disrupt log collection, the risk of arbitrary code execution has not been demonstrated. Users should update to version 8.2604.0 or later to mitigate this vulnerability.

Affected Version(s)

rsyslog >= 8.2110.0, < 8.2604.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.