CVE-2026-39879 Details
Description
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
A SQL injection vulnerability has been identified in syslog-ng versions prior to 4.12, as well as in syslog-ng Premium Edition versions prior to 8.2 and syslog-ng Store Box versions prior to 7.8. The issue arises from a missing sanitization call in the AFSQl destination driver, allowing untrusted sources to inject malicious SQL. This vulnerability is not part of the default configuration and requires the SQL driver to be manually enabled.
Users can update to syslog-ng 4.12, syslog-ng Premium Edition 8.2, or syslog-ng Store Box 7.8 to address this vulnerability. If the SQL driver is used, implement server-side query sanitization as an additional precaution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-150 | Improper Neutralization of Escape, Meta, or Control Sequences | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| syslog-ng | < 4.12 |
CPE
Remediation
| |
| syslog-ng Premium Edition | < 8.2 |
CPE
Remediation
| |
| syslog-ng Store Box | < 7.8 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion