<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:18:34.710363+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362184</id>
    <title>EUVD-2026-362184</title>
    <updated>2026-10-04T09:18:34.713527+00:00</updated>
    <content>EUVD-2026-362184</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55841</id>
    <title>fkie_cve-2026-55841</title>
    <updated>2026-10-04T09:18:34.713559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gqr6-r77p-c2pj</id>
    <title>GHSA-gqr6-r77p-c2pj — Fortigate syslog message parser can be exploited to modify or delete fields from the original message</title>
    <updated>2026-10-04T09:18:34.713595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.graylog2:graylog2-server</p>
<p>### Impact</p>
<p>A security issue has been identified in Graylog affecting the parsing of syslog messages that use a key-value format, such as those generated by Fortigate devices.</p>
<p>The vulnerability allows attackers to overwrite individual message fields, or to produce invalid messages which Graylog will discard. This effectively enables log evasion techniques to obscure malicious activity.</p>
<p>### Patches</p>
<p>The issue has been fixed in the following Graylog versions: `6.3.12`, `7.0.7`, `7.1.2`. Users should upgrade to one of these versions or above to remediate the vulnerability.</p>
<p>Graylog Cloud has already been patched.</p>
<p>### Workarounds</p>
<p>There are no feasible workarounds for this issue. Upgrading to a patched version is recommended.</p>
<p>To find potentially discarded messages due to parsing errors, customers of Graylog Enterprise or Security can check the Indexing and Processing Failures Index[^1].</p>
<p>### Credits</p>
<p>Thanks to Jose Luis González, from Fundación Sarenet, with additional analysis by Borja Marcos from Sarenet.</p>
<p>[^1]: https://go2docs.graylog.org/current/getting_in_log_data/indexer_and_processing_failures.html</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gqr6-r77p-c2pj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3088</id>
    <title>WID-SEC-W-2026-3088 — Graylog: Mehrere Schwachstellen</title>
    <updated>2026-10-04T09:18:34.713637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Graylog ausnutzen, um Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3088"/>
  </entry>
</feed>
