PT-2026-52219 · Debian+1 · Rsyslog

CVE-2026-55556

·

Published

2026-06-23

·

Updated

2026-06-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions rsyslog (affected versions not specified)
Description A heap overflow exists in the imhttp module, which is used for receiving logs via HTTP. This issue occurs when HTTP Basic Authentication is enabled and can be triggered by an attacker with access to the HTTP endpoint. The imhttp module must be built, installed, loaded, and configured for the issue to be exploitable.
Recommendations As a temporary workaround, disable HTTP Basic Authentication or restrict access to the imhttp endpoint to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-55556

Affected Products

Rsyslog