Vulnerabilities (CVE)

Filtered by vendor Cribl Subscribe
Filtered by product Cribl Stream
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-56748 1 Cribl 1 Cribl Stream 2026-08-20 N/A 8.8 HIGH
Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.
CVE-2026-56747 1 Cribl 1 Cribl Stream 2026-08-20 N/A 8.8 HIGH
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value.