๐Ÿ” CVE Alert

CVE-2026-54715

UNKNOWN 0.0

GoAccess: Heap Out-of-Bounds Write in parse_browser()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.

CWE CWE-122 CWE-787
Vendor allinurl
Product goaccess
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for allinurl goaccess

Be the first to know when new unknown vulnerabilities affecting allinurl goaccess are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

allinurl / goaccess
>= 1.10.2, < 1.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr github.com: https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351