Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Allinurl
Allinurl goaccess |
|
| Vendors & Products |
Allinurl
Allinurl goaccess |
Fri, 31 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed access log to read up to approximately 4 KB beyond the heap allocation and conditionally crash GoAccess. This issue is fixed in version 1.11. | |
| Title | GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads to remote crash/DoS | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T11:24:05.795Z
Reserved: 2026-06-17T14:40:28.379Z
Link: CVE-2026-55777
Updated: 2026-07-31T11:23:37.581Z
Status : Received
Published: 2026-07-30T21:17:57.360
Modified: 2026-07-31T12:16:51.520
Link: CVE-2026-55777
No data.
OpenCVE Enrichment
Updated: 2026-08-03T10:30:18Z