org.graylog2:graylog2-server
Maven15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.graylog2:graylog2-serverpage 1 of 1
- CVE-2018-11650MEDIUMCVSS 6.1EG 6.1fixed in 2.4.42018-06-01
vulnerable: 0.20.0-rc.1-1 ... 2.4.3 (117 versions)
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
- CVE-2018-11651MEDIUMCVSS 6.1EG 6.1fixed in 2.4.42018-06-01
vulnerable: 0.20.0-rc.1-1 ... 2.4.3 (117 versions)
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
- CVE-2018-14380MEDIUMCVSS 6.1EG 6.1fixed in 2.4.62018-07-18
vulnerable: 0.20.0-rc.1-1 ... 2.4.5 (119 versions)
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
- CVE-2023-41041LOWCVSS 3.1EG 3.1fixed in 5.0.9 or 5.1.3, by version range2023-08-30
vulnerable: 5.1.0, 5.1.1, 5.1.2
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests until it has reached its original expiry time. Each node maintai…
- CVE-2023-41044LOWCVSS 3.8EG 3.8fixed in 5.1.32023-08-31
vulnerable: 5.1.0, 5.1.1, 5.1.2
Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an HTTP API resource. Graylog's Supp…
- CVE-2023-41045MEDIUMCVSS 5.3EG 5.3fixed in 5.1.3 or 5.0.9, by version range2023-08-31
vulnerable: 0.20.0-rc.1-1 ... 5.0.8 (251 versions)
Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket for outgoing DNS queries and while that socket is bound to a random port number it is never…
- CVE-2024-24823MEDIUMCVSS 5.7EG 5.7fixed in 5.1.11 or 5.2.4, by version range2024-02-07
vulnerable: 5.2.0 ... 5.2.3 (10 versions)
Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthenticating with an existing session cookie would re-use that session id, even if for different user credentials. In…
- CVE-2024-24824HIGHCVSS 8.8EG 8.8fixed in 5.1.11 or 5.2.4, by version range2024-02-07
vulnerable: 5.2.0 ... 5.2.3 (10 versions)
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. …
- CVE-2025-30373MEDIUMCVSS 6.5EG 6.5fixed in 6.1.92025-04-07
vulnerable: 6.1.0 ... 6.1.8 (8 versions)
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in ca…
- CVE-2025-46827HIGHCVSS 8.0EG 8.0fixed in 6.0.14 or 6.1.10, by version range2025-05-07
vulnerable: 6.1.0 ... 6.1.8 (8 versions)
Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attac…
- CVE-2025-53106HIGHCVSS 8.8EG 8.8fixed in 6.2.4 or 6.3.0-rc.2, by version range2025-07-02
vulnerable: 6.2.0, 6.2.1, 6.2.2, 6.2.3
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating and using API tokens for the local Administrator or any ot…
- CVE-2026-55425MEDIUMCVSS 5.0EG 5.0fixed in 7.1.42026-08-28
vulnerable: 7.1.1, 7.1.2, 7.1.3
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServ…
- CVE-2026-55841HIGHCVSS 7.5EG 7.5fixed in 6.3.12, 7.0.7 or 7.1.2, by version range2026-08-28
vulnerable: 7.1.1
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/cod…
- CVE-2026-55867MEDIUMCVSS 5.3EG 5.3fixed in 6.3.12, 7.0.7 or 7.1.2, by version range2026-08-28
vulnerable: 7.1.1
Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/…
- CVE-2026-69190MEDIUMCVSS 6.3EG 6.3fixed in 6.3.14, 7.0.9 or 7.1.4, by version range2026-09-21
vulnerable: 7.1.1, 7.1.2, 7.1.3
Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest…
Check whether org.graylog2:graylog2-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.graylog2:graylog2-server CVEs against the assets you own.
Book a Demo →