Unrated severityNVD Advisory· Published Jul 31, 2026
Debian goaccess: GoAccess is a real-time web log analyzer and interactive viewer that runs in a t…
CVE-2026-54715
Description
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.
Affected products
1Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.