---
id: CVE-2026-55768
title: >-
  GoAccess is a real-time web log analyzer and interactive viewer that runs in a
  terminal in *nix systems or through the browser
summary: >-
  GoAccess is a real-time web log analyzer and interactive viewer that runs in a
  terminal in *nix systems or through the browser. Prior to version 1.11, the
  built-in WebSocket server narrows a 64-bit extended frame length into the
  signed 3…
severity: none
cwe:
  - CWE-681
  - CWE-789
published: '2026-07-30'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55768'
references:
  - url: >-
      https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5
    label: security-advisories@github.com
  - url: >-
      https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
    label: security-advisories@github.com
  - url: >-
      https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00472
epssPercentile: 0.38144
ingestedAt: '2026-08-01T22:15:46.350Z'
---

## Overview

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
