HIGH 7.5 NVD
CVE-2026-19654
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery ca
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
References
- https://access.redhat.com/security/cve/CVE-2026-19654
- https://bugzilla.redhat.com/show_bug.cgi?id=2502868
- https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-12 via NVD.
vulnfeed aggregates 10530 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.