Executive brief
Rsyslog's imhttp module handles incoming log data via HTTP with optional Basic Authentication. An unauthenticated attacker sending a malformed HTTP Basic Authorization header can crash the rsyslog process, disrupting log collection. This affects only deployments that explicitly load and configure the imhttp module with Basic Authentication enabled.
Technical details
The imhttp module's parse_auth_header function allocates a zero-byte heap buffer when an HTTP Basic Authorization credential exceeds its fixed-size work buffer, then passes the invalid pointer to apr_base64_decode for decoding. This allows heap memory corruption before credential validation. The vulnerability is reachable by unauthenticated remote attackers over the network if imhttp with Basic Authentication is configured; current impact is denial of service via process crash.
Affected products
- rsyslog rsyslog 8.2110.0 to 8.2603.0
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: Fixed in version 8.2604.0