Junglewise Threat Intelligence

CVE-2026-55556: Rsyslog imhttp heap buffer overflow in Basic Authentication parsing

CVE-2026-55556 · Severity: info · Published 2026-09-18

Technologies: Rsyslog. Vendors: Rsyslog.

Executive brief

Rsyslog's imhttp module handles incoming log data via HTTP with optional Basic Authentication. An unauthenticated attacker sending a malformed HTTP Basic Authorization header can crash the rsyslog process, disrupting log collection. This affects only deployments that explicitly load and configure the imhttp module with Basic Authentication enabled.

Technical details

The imhttp module's parse_auth_header function allocates a zero-byte heap buffer when an HTTP Basic Authorization credential exceeds its fixed-size work buffer, then passes the invalid pointer to apr_base64_decode for decoding. This allows heap memory corruption before credential validation. The vulnerability is reachable by unauthenticated remote attackers over the network if imhttp with Basic Authentication is configured; current impact is denial of service via process crash.

Affected products

  • rsyslog rsyslog 8.2110.0 to 8.2603.0

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Fixed in version 8.2604.0

References

Related threats