CVE-2026-55841 | Graylog up to 6.3.11/7.0.6/7.1.1 FortiGate key-value syslog parser GLFortiGateSyslogEvent.java GLFortiGateSyslogEvent.getFields escape output
A vulnerability labeled as problematic has been found in Graylog up to 6.3.11/7.0.6/7.1.1. Affected by this issue is the function GLFortiGateSyslogEvent.getFields of the file graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java of the component FortiGate key-value syslog parser. Such manipulation leads to escaping of output.
This vulnerability is referenced as CVE-2026-55841. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.VulDB Recent EntriesRead More