What is CVE-2026-55768?
CVE-2026-55768 in GoAccess, before version 1.11, involves the built-in WebSocket server narrowing a 64-bit extended frame length into a signed 32-bit field before enforcing the maximum frame size check. This can allow bypassing length restrictions. Users should upgrade to version 1.11 or later.
Azərbaycanca: GoAccess real-time web log analizatorunda aşkar olunmuş CVE-2026-55768 zəifliyi 1.11 versiyasından əvvəl daxili WebSocket serverində 64-bitlik frame uzunluğunun 32-bitlik işarəli sahəyə sığdırılması nəticəsində baş verir. Bu, frame uzunluğu yoxlanışından yan keçməyə imkan yaradır. İstifadəçilər GoAccess-i 1.11 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which component of GoAccess does CVE-2026-55768 affect?
The vulnerability affects the built-in WebSocket server of GoAccess.
What should users do to mitigate CVE-2026-55768?
Users should upgrade to GoAccess version 1.11 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.