๐Ÿ” CVE Alert

CVE-2026-55777

UNKNOWN 0.0

GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads to remote crash/DoS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed access log to read up to approximately 4 KB beyond the heap allocation and conditionally crash GoAccess. This issue is fixed in version 1.11.

CWE CWE-125
Vendor allinurl
Product goaccess
Published Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for allinurl goaccess

Be the first to know when new unknown vulnerabilities affecting allinurl goaccess are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

allinurl / goaccess
< 1.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg github.com: https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81