CVE-2026-39879

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-20 17:17

Updated : 2026-07-23 16:04


NVD link : CVE-2026-39879

Mitre link : CVE-2026-39879

CVE.ORG link : CVE-2026-39879


JSON object : View

Products Affected

No product.

CWE
CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences