<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 08:23:04 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-39879</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-39879</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: syslog-ng, Alpaquita:25: syslog-ng, Alpaquita:stream: syslog-ng&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: syslog-ng, Alpaquita:25: syslog-ng, Alpaquita:stream: syslog-ng&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-39879</guid>
    </item>
    <item>
      <title>EUVD-2026-339218</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339218</link>
      <description>EUVD-2026-339218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339218</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39879</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39879</link>
      <description>&lt;p&gt;Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.&lt;/p&gt;
&lt;p&gt;Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.&lt;/p&gt;
&lt;p&gt;Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39879</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-39879 — SQL injection in syslog-ng SQL destionation driver</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-39879</link>
      <description>msrc_CVE-2026-39879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-39879</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-39879</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39879</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: syslog-ng, Ubuntu:16.04:LTS: syslog-ng, Ubuntu:18.04:LTS: syslog-ng, Ubuntu:20.04:LTS: syslog-ng, Ubuntu:22.04:LTS: syslog-ng, Ubuntu:24.04:LTS: syslog-ng, Ubuntu:26.04:LTS: syslog-ng&lt;/p&gt;
&lt;p&gt;Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: syslog-ng, Ubuntu:16.04:LTS: syslog-ng, Ubuntu:18.04:LTS: syslog-ng, Ubuntu:20.04:LTS: syslog-ng, Ubuntu:22.04:LTS: syslog-ng, Ubuntu:24.04:LTS: syslog-ng, Ubuntu:26.04:LTS: syslog-ng&lt;/p&gt;
&lt;p&gt;Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39879</guid>
    </item>
  </channel>
</rss>
