Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.
Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
References
Configurations
No configuration.
History
20 Jul 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-20 17:17
Updated : 2026-07-21 17:17
NVD link : CVE-2026-39879
Mitre link : CVE-2026-39879
CVE.ORG link : CVE-2026-39879
JSON object : View
Products Affected
No product.
CWE
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
