CVE-2026-55768

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 21:17

Updated : 2026-09-08 20:51


NVD link : CVE-2026-55768

Mitre link : CVE-2026-55768

CVE.ORG link : CVE-2026-55768


JSON object : View

Products Affected

No product.

CWE
CWE-681

Incorrect Conversion between Numeric Types

CWE-789

Memory Allocation with Excessive Size Value