Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

graylog2-server — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in graylog2-server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerability data for graylog2-server, focusing on the Common Weakness Enumeration (CWE) taxonomy as categorized by the vendor. It compiles a comprehensive list of security flaws affecting this specific server application, covering reported issues from early releases through the most recent updates. By examining this collection, users can track advisory patterns issued by the vendor to understand the evolving threat landscape for this logging platform. Visitors are encouraged to use this resource to investigate historical vulnerability trends, identify recurring weakness classes that have impacted the software over time, and gain insight into the product's security posture across different versions. This aggregation serves as a neutral reference for security researchers, system administrators, and auditors who need to assess the integrity and stability of graylog2-server deployments. The data is organized to facilitate easy navigation, allowing stakeholders to quickly locate relevant information without sifting through unrelated noise. Understanding these historical vulnerabilities helps in prioritizing patch management and hardening strategies, ensuring that known issues are addressed proactively. The scope includes a wide variety of common security defects, ranging from buffer overflows to authentication bypasses, providing a holistic view of the product's security history. This page is strictly informational and does not provide remediation steps or official patches, directing users to the vendor’s official channels for actionable solutions.

Vendor: Graylog2

CVE ID Title CVSS Severity Published
CVE-2026-69190 Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards CWE-639 6.3 Medium 2026-09-21
CVE-2026-92789 Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect CWE-918 6.5 Medium 2026-09-16
CVE-2026-55867 Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens CWE-639 5.3 Medium 2026-08-28
CVE-2026-55841 Graylog: Fortigate syslog message parser can be exploited to modify or delete fields from the original message CWE-138 7.5 High 2026-08-28
CVE-2026-55425 Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields CWE-213 5.0 Medium 2026-08-28
CVE-2026-65011 Graylog2 Server Missing Permission Check on Event Definition Duplicate CWE-862 4.3 Medium 2026-07-22
CVE-2025-53106 Graylog vulnerable to privilege escalation through API tokens CWE-285 8.8AI High AI 2025-07-02
CVE-2025-46827 Graylog Allows Session Takeover via Insufficient HTML Sanitization CWE-79 8.0 High 2025-05-07
CVE-2025-30373 Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value CWE-285 6.5 Medium 2025-04-07
CVE-2024-52506 Graylog can leak other users' reports via concurrent PDF report rendering CWE-200 4.3AI Medium AI 2024-11-18
CVE-2024-24824 graylog2-server vulnerable to instantiation of arbitrary classes triggered by API request CWE-284 8.8 High 2024-02-07
CVE-2024-24823 graylog2-server Session Fixation vulnerability through cookie injection CWE-384 5.7 Medium 2024-02-07
CVE-2023-41045 Insecure source port usage for DNS queries in Graylog CWE-345 3.7 Low 2023-08-31
CVE-2023-41044 Partial path traversal vulnerability in Support Bundle feature of Graylog CWE-22 3.3 Low 2023-08-31
CVE-2023-41041 User session is still usable after logout in graylog2-server CWE-613 2.6 Low 2023-08-30

All 15 known CVE vulnerabilities affecting graylog2-server with full Chinese analysis, references, and POCs where available.