{"id":"CVE-2026-55841","description":"Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and graylog2-server/src/main/java/org/graylog2/inputs/codecs/SyslogCodec.java mishandles field-like text inside quoted values. GLFortiGateSyslogEvent.getFields() uses KV_PATTERN and QUOTED_KV_PATTERN, while SyslogCodec.parse() invokes the FortiGateSyslogEvent parser; crafted values containing = or backslash-escaped quotes can cause embedded keys such as srcip, dstip, date, time, and tz to remove or overwrite original top-level fields or produce an invalid message that Graylog discards. An unauthenticated network sender who can submit syslog messages can therefore manipulate security-log fields or evade logging to obscure malicious activity. This issue is fixed in Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3.","cvssScore":7.5,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssMetrics":[{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","source":"security-advisories@github.com","type":"Secondary"}],"cwes":["CWE-138"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2026-08-28","lastModified":"2026-09-09","references":[{"url":"https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f","source":"patch-hint","tags":["commit"]},{"url":"https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-gqr6-r77p-c2pj","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/pull/26050","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/pull/26056","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/pull/26057","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/pull/26059","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/commit/85dc699d6319aea433583dc239077a3a799c8627","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/commit/d5051e604c962ef3d4e5e8e434d0ff4907d2140d","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server/commit/dde76d7432c469887d9a95c208083c5f0f73c70d","source":"osv","tags":["WEB"]},{"url":"https://github.com/Graylog2/graylog2-server","source":"osv","tags":["PACKAGE"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.graylog2:graylog2-server"},{"rule":"patch-hint","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"References include candidate fix URL (commit tier): https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f"},{"rule":"open-source-maven","stage":"disposition","outcome":"skipped"},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"no-match","detail":"Severity is HIGH — only MEDIUM/LOW are deprioritized"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"patchHintUrl":"https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f","patchHintTier":"commit","affectedPackages":[{"name":"org.graylog2:graylog2-server","introduced":"0","fixed":"6.3.12"},{"name":"org.graylog2:graylog2-server","introduced":"7.0.0","fixed":"7.0.7"},{"name":"org.graylog2:graylog2-server","introduced":"7.1.0","fixed":"7.1.2"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00355,"percentile":0.28859},"ssvc":{"available":true,"exploitation":"none","automatable":"yes","technicalImpact":"partial"},"patchHintUrl":"https://github.com/Graylog2/graylog2-server/commit/793df6e8202ea55c15a762e47a2a8a775961dd3f","patchHintTier":"commit"}