What is CVE-2026-55777?
CVE-2026-55777 is a vulnerability in GoAccess's parse_ios() function where an attacker-controlled keyword-to-OS offset is used as both source and length for memmove, leading to potential memory corruption. This affects versions prior to 1.11, and immediate update is recommended.
Azərbaycanca: CVE-2026-55777 GoAccess real-time web log analizatorunda parse_ios() funksiyasında memmove əməliyyatı zamanı təhlükəsizlik zəifliyidir. Təcavüzkar xüsusi hazırlanmış User-Agent vasitəsilə yaddaş korrupsiyasına səbəb ola bilər. 1.11 versiyasından əvvəlki versiyalar təsirlənir, dərhal yenilənmə tövsiyə olunur.
FAQ2
In which function of GoAccess was the CVE-2026-55777 vulnerability discovered?
CVE-2026-55777 was discovered in the parse_ios() function of the GoAccess real-time web log analyzer.
How can an attacker exploit the CVE-2026-55777 vulnerability?
An attacker can cause potential memory corruption via a specially crafted User-Agent.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.