Information Exposure Affecting org.graylog2:graylog2-server package, versions [7.1.0,7.1.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGGRAYLOG2-19433286
  • published31 Aug 2026
  • disclosed28 Aug 2026
  • creditEvelynkaz

Introduced: 28 Aug 2026

NewCVE-2026-55425  (opens in a new tab)
CWE-213  (opens in a new tab)

How to fix?

Upgrade org.graylog2:graylog2-server to version 7.1.4 or higher.

Overview

org.graylog2:graylog2-server is a log management platform.

Affected versions of this package are vulnerable to Information Exposure in the system catalog entity titles API endpoint, which returns requested database fields without filtering out ones marked protected. A user with a standard account can retrieve their own password hash, and an administrator can retrieve every user's password hash, by requesting those protected fields through this endpoint. This requires an authenticated account, and a standard user is limited to their own record while an administrator can read all users' records.

CVSS Base Scores

version 4.0
version 3.1