Vulnerability in GoAccess Real-Time Web Log Analyzer by Allinurl
CVE-2026-55768

8.7HIGH

Key Information:

Vendor

Allinurl

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-55768?

The GoAccess real-time web log analyzer, utilized on various *nix systems, has a vulnerability related to its built-in WebSocket server. Versions prior to 1.11 allow an unauthenticated remote client to exploit the WSFrame.payloadlen field, which incorrectly narrows a 64-bit extended frame length to a signed 32-bit integer. This flaw enables an attacker to bypass security measures, potentially leading to an excessive memory allocation request of around 18 exabytes, ultimately causing the application to terminate unexpectedly. Users are encouraged to upgrade to version 1.11 or later to mitigate this risk.

Affected Version(s)

goaccess < 1.11

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.