PT-2026-66592 · Goaccess · Goaccess

CVE-2026-54715

·

Published

2026-07-30

·

Updated

2026-08-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GoAccess versions prior to 1.11
Description The parse browser() function incorrectly handles browser tokens starting with Opera. It moves a trailing version substring to a position that allows a crafted User-Agent in a processed access log to write one to four bytes beyond the heap allocation. This heap-based buffer overflow can lead to memory corruption or cause the application to crash.
Recommendations Update GoAccess to version 1.11.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54715
GHSA-QCX5-VH2X-35FR
OESA-2026-3263

Affected Products

Goaccess