HIGH 7.1 NVD
CVE-2026-54715
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.
References
- https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351
- https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
- https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-07-30 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.