graylog2 has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 6.4 (medium). None have a confirmed exploitation report. Most affected products: org.graylog2:graylog2-server (3), graylog2-server (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Products
- org.graylog2:graylog2-server 3
- graylog2-server 2
Worst active — by depth score
CVE-2026-55841High· 7.5Graylog is a free and open log management platform41CVE-2026-92789Medium· 6.5Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects36CVE-2026-69190Medium· 6.3Graylog is a free and open log management platform35CVE-2026-55867MediumGraylog is a free and open log management platform28CVE-2026-55425Medium· 5.0Graylog is a free and open log management platform28
graylog2 vulnerabilities
CVEs affecting graylog2, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-69190Medium· 6.3Graylog is a free and open log management platform
Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareReque…
CVE-2026-92789Medium· 6.5Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects
Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoi…
CVE-2026-55841High· 7.5Graylog is a free and open log management platform
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/c…
CVE-2026-55867MediumGraylog is a free and open log management platform
Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog…
CVE-2026-55425Medium· 5.0Graylog is a free and open log management platform
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleSe…