CVE-2026-78002CWE-131

CVE-2026-78002

High · published August 27, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
47.0
In the wild
Unconfirmed
What it is

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00612 · 47.0th percentile
Weakness
CWE-131 · Incorrect Calculation of Buffer Size
Published
2026-08-27T21:20Z
References (4)
EPSS history
Timeline
  • 27 AUG 16:12Z
    Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function
    cvelistv5