Memory Corruption Vulnerability in GoAccess Web Log Analyzer
CVE-2026-55777
5.3MEDIUM
What is CVE-2026-55777?
GoAccess, a real-time web log analyzer, is susceptible to a memory corruption issue due to improper handling of User-Agent strings in access logs. An attacker can manipulate a specially crafted User-Agent that triggers the parse_ios() function, allowing them to read memory beyond the allocated heap, which may lead to application crashes. This vulnerability affects versions prior to 1.11 but is resolved in the latest release.
Affected Version(s)
goaccess < 1.11
