Graylog Allows Session Takeover via Insufficient HTML Sanitization
High8.0CVE-2025-46827 · Published May 7, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.graylog2:graylog2-server Maven | < 6.0.14 | 6.0.14 |
| >= 6.1.0, < 6.1.10 | 6.1.10 |
Details and references
### Impact It is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permissions to create event definitions, while the user must have permissions to view alerts. Additionally, an active Input must be present on the Graylog server that is capable of receiving form data (e.g. a HTTP input, TCP raw or syslog etc). ### Patches ### Workarounds None, as long as the relatively rare prerequisites are met. Analysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2025-46827
More graylog2-server advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 72025 | Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser GHSA-q9q2-3ppx-mwqfHigh7.3fixed in 6.2.0 | High7.3 | 6.2.0 |
| Apr 72025 | Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value CVE-2025-30373Medium6.5fixed in 6.1.9 | Medium6.5 | 6.1.9 |
| Jun 302025 | Graylog vulnerable to privilege escalation through API tokens CVE-2025-53106Highfixed in 6.2.4, 6.3.0-rc.2 | High | 6.2.4, 6.3.0-rc.2 |
| Feb 72024 | Graylog session fixation vulnerability through cookie injection CVE-2024-24823Medium5.7fixed in 5.1.11, 5.2.4 | Medium5.7 | 5.1.11, 5.2.4 |
| Feb 72024 | Graylog vulnerable to instantiation of arbitrary classes triggered by API request CVE-2024-24824High8.8fixed in 5.1.11, 5.2.4 | High8.8 | 5.1.11, 5.2.4 |
| Aug 28 | Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields CVE-2026-55425Medium5.0fixed in 7.1.4 | Medium5.0 | 7.1.4 |