← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 20:46via CVEFeed

CVE-2026-19654 - Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

Brief

CVE ID : CVE-2026-19654

Published : Aug. 12, 2026, 8:46 p. m.

  • 18 minutes ago

Description : A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

Severity: 7.5

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed