High severity7.1OSV Advisory· Published Jul 20, 2026· Updated Jul 23, 2026
CVE-2026-39879
CVE-2026-39879
Description
Due to a missing sanitization call in `afsql_dd_run_query`, syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.
Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.