rsyslog has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
rsyslog vulnerabilities
CVEs affecting rsyslog, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-61548High· 8.1Rsyslog is a rocket-fast system for log processing
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] st…
CVE-2026-55556High· 8.2Rsyslog is a rocket-fast system for log processing
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic…
CVE-2026-19654High· 7.5A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confide…