<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T12:32:06.440885+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-39879</id>
    <title>BELL-CVE-2026-39879</title>
    <updated>2026-10-05T12:32:06.533292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: syslog-ng, Alpaquita:25: syslog-ng, Alpaquita:stream: syslog-ng</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-39879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339218</id>
    <title>EUVD-2026-339218</title>
    <updated>2026-10-05T12:32:06.533360+00:00</updated>
    <content>EUVD-2026-339218</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39879</id>
    <title>fkie_cve-2026-39879</title>
    <updated>2026-10-05T12:32:06.533387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.</p>
<p>Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-39879</id>
    <title>msrc_CVE-2026-39879 — SQL injection in syslog-ng SQL destionation driver</title>
    <updated>2026-10-05T12:32:06.533433+00:00</updated>
    <content>msrc_CVE-2026-39879</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-39879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39879</id>
    <title>UBUNTU-CVE-2026-39879</title>
    <updated>2026-10-05T12:32:06.533462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: syslog-ng, Ubuntu:16.04:LTS: syslog-ng, Ubuntu:18.04:LTS: syslog-ng, Ubuntu:20.04:LTS: syslog-ng, Ubuntu:22.04:LTS: syslog-ng, Ubuntu:24.04:LTS: syslog-ng, Ubuntu:26.04:LTS: syslog-ng</p>
<p>Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39879"/>
  </entry>
</feed>
