PT-2026-66594 · Goaccess · Goaccess

CVE-2026-55777

·

Published

2026-07-30

·

Updated

2026-08-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GoAccess versions prior to 1.11
Description The parse ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove. This allows a crafted User-Agent in a processed access log to read approximately 4 KB beyond the heap allocation, which can lead to a conditional crash of the application.
Recommendations Update to version 1.11.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55777
GHSA-5PHR-QPGF-HGRG
OESA-2026-3263

Affected Products

Goaccess