Source: goaccess
Version: 1:1.10.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for goaccess.

CVE-2026-54715[0]:
| GoAccess is a real-time web log analyzer and interactive viewer that
| runs in a terminal in *nix systems or through the browser. In
| version 1.10.2, parse_browser assumes the matched browser token
| begins with Opera and moves a trailing version substring to match
| plus five, allowing a crafted User-Agent in a processed access log
| to write one to four attacker-influenced bytes beyond the heap
| allocation and corrupt or crash GoAccess. This issue is fixed in
| version 1.11.


CVE-2026-55768[1]:
| GoAccess is a real-time web log analyzer and interactive viewer that
| runs in a terminal in *nix systems or through the browser. Prior to
| version 1.11, the built-in WebSocket server narrows a 64-bit
| extended frame length into the signed 32-bit WSFrame.payloadlen
| field before enforcing the maximum frame size, allowing an
| unauthenticated remote client to bypass the guard and force an
| approximately 18-exabyte allocation request that terminates the
| process. This issue is fixed in version 1.11.


CVE-2026-55777[2]:
| GoAccess is a real-time web log analyzer and interactive viewer that
| runs in a terminal in *nix systems or through the browser. Prior to
| 1.11, the parse_ios() function uses an attacker-controlled keyword-
| to-OS offset as both the source offset and copy length for memmove,
| allowing a crafted User-Agent in a processed access log to read up
| to approximately 4 KB beyond the heap allocation and conditionally
| crash GoAccess. This issue is fixed in version 1.11.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54715
    https://www.cve.org/CVERecord?id=CVE-2026-54715
[1] https://security-tracker.debian.org/tracker/CVE-2026-55768
    https://www.cve.org/CVERecord?id=CVE-2026-55768
[2] https://security-tracker.debian.org/tracker/CVE-2026-55777
    https://www.cve.org/CVERecord?id=CVE-2026-55777

Regards,
Salvatore

Reply via email to