Skip to content
graylog2-serverGHSA-76vf-mpmx-777j

Graylog Allows Session Takeover via Insufficient HTML Sanitization

High8.0CVE-2025-46827 · Published May 7, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
org.graylog2:graylog2-server
Maven
< 6.0.146.0.14
>= 6.1.0, < 6.1.106.1.10
Details and references

### Impact It is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permissions to create event definitions, while the user must have permissions to view alerts. Additionally, an active Input must be present on the Graylog server that is capable of receiving form data (e.g. a HTTP input, TCP raw or syslog etc). ### Patches ### Workarounds None, as long as the relatively rare prerequisites are met. Analysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2025-46827

More graylog2-server advisories

All
DateAdvisory
May 72025Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
GHSA-q9q2-3ppx-mwqfHigh7.3fixed in 6.2.0
Apr 72025Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
CVE-2025-30373Medium6.5fixed in 6.1.9
Jun 302025Graylog vulnerable to privilege escalation through API tokens
CVE-2025-53106Highfixed in 6.2.4, 6.3.0-rc.2
Feb 72024Graylog session fixation vulnerability through cookie injection
CVE-2024-24823Medium5.7fixed in 5.1.11, 5.2.4
Feb 72024Graylog vulnerable to instantiation of arbitrary classes triggered by API request
CVE-2024-24824High8.8fixed in 5.1.11, 5.2.4
Aug 28Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
CVE-2026-55425Medium5.0fixed in 7.1.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.