VulnSea

graylog2 has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 6.4 (medium). None have a confirmed exploitation report. Most affected products: org.graylog2:graylog2-server (3), graylog2-server (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.4
Publish → KEV
Last 90 days
5 prev 0

Products

  • org.graylog2:graylog2-server 3
  • graylog2-server 2
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

graylog2 vulnerabilities

CVEs affecting graylog2, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-69190Medium· 6.3
yesterday

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareReque…

SunlitGraylog2 · graylog2-servervia NVD
CVE-2026-92789Medium· 6.5
6d ago

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoi…

SunlitGraylog2 · graylog2-serverEPSS 0.30%via NVD
CVE-2026-55841High· 7.5
3w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/c…

Twilightgraylog2 · org.graylog2:graylog2-serverEPSS 0.36%via NVD
CVE-2026-55867Medium
3w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog…

Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.34%via NVD
CVE-2026-55425Medium· 5.0
3w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleSe…

Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.30%via NVD
graylog2 vulnerabilities (CVEs) · VulnSea