Improper Neutralization of Special Elements Affecting org.graylog2:graylog2-server package, versions [,6.3.12)[7.0.0,7.0.7)[7.1.1,7.1.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.36% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGGRAYLOG2-19457545
  • published1 Sept 2026
  • disclosed28 Aug 2026
  • creditJose Luis Gonzalez Calvo

Introduced: 28 Aug 2026

NewCVE-2026-55841  (opens in a new tab)
CWE-138  (opens in a new tab)

How to fix?

Upgrade org.graylog2:graylog2-server to version 6.3.12, 7.0.7, 7.1.2 or higher.

Overview

org.graylog2:graylog2-server is a log management platform.

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in its syslog key-value message parser, which handles the key-value format emitted by Fortigate devices. An attacker can overwrite fields in the parsed log record, or force the message to be discarded to evade logging, by embedding key-value delimiter characters in the syslog message they send. This requires the deployment to ingest key-value format syslog messages, such as Fortigate logs, and the attacker to be able to send or influence those messages.

CVSS Base Scores

version 4.0
version 3.1