Source: goaccess Version: 1:1.10.1-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for goaccess. CVE-2026-54715[0]: | GoAccess is a real-time web log analyzer and interactive viewer that | runs in a terminal in *nix systems or through the browser. In | version 1.10.2, parse_browser assumes the matched browser token | begins with Opera and moves a trailing version substring to match | plus five, allowing a crafted User-Agent in a processed access log | to write one to four attacker-influenced bytes beyond the heap | allocation and corrupt or crash GoAccess. This issue is fixed in | version 1.11. CVE-2026-55768[1]: | GoAccess is a real-time web log analyzer and interactive viewer that | runs in a terminal in *nix systems or through the browser. Prior to | version 1.11, the built-in WebSocket server narrows a 64-bit | extended frame length into the signed 32-bit WSFrame.payloadlen | field before enforcing the maximum frame size, allowing an | unauthenticated remote client to bypass the guard and force an | approximately 18-exabyte allocation request that terminates the | process. This issue is fixed in version 1.11. CVE-2026-55777[2]: | GoAccess is a real-time web log analyzer and interactive viewer that | runs in a terminal in *nix systems or through the browser. Prior to | 1.11, the parse_ios() function uses an attacker-controlled keyword- | to-OS offset as both the source offset and copy length for memmove, | allowing a crafted User-Agent in a processed access log to read up | to approximately 4 KB beyond the heap allocation and conditionally | crash GoAccess. This issue is fixed in version 1.11. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54715 https://www.cve.org/CVERecord?id=CVE-2026-54715 [1] https://security-tracker.debian.org/tracker/CVE-2026-55768 https://www.cve.org/CVERecord?id=CVE-2026-55768 [2] https://security-tracker.debian.org/tracker/CVE-2026-55777 https://www.cve.org/CVERecord?id=CVE-2026-55777 Regards, Salvatore

