Vulnerability Description
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8
- https://github.com/Graylog2/graylog2-server/commit/85dc699d6319aea433583dc239077
- https://github.com/Graylog2/graylog2-server/commit/d5051e604c962ef3d4e5e8e434d0f
- https://github.com/Graylog2/graylog2-server/commit/dde76d7432c469887d9a95c208083
- https://github.com/Graylog2/graylog2-server/pull/26050
- https://github.com/Graylog2/graylog2-server/pull/26056
- https://github.com/Graylog2/graylog2-server/pull/26057
- https://github.com/Graylog2/graylog2-server/pull/26059
- https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-gqr6-r77p-c
FAQ
What is CVE-2026-55841?
CVE-2026-55841 is a vulnerability with a CVSS score of 7.5 (HIGH). Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-serve...
How severe is CVE-2026-55841?
CVE-2026-55841 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55841?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.