Skip to content

Graylog security advisories

16 advisories across Graylog

Company profile
Advisory
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
Medium6.3Sep 22
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
MediumAug 28
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
High7.5Aug 28
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
Medium5.0Aug 28
Graylog vulnerable to privilege escalation through API tokens
HighJun 30, 2025
Graylog Allows Session Takeover via Insufficient HTML Sanitization
High8.0May 7, 2025
Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
High7.3May 7, 2025
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Medium6.5Apr 7, 2025
Graylog session fixation vulnerability through cookie injection
Medium5.7Feb 7, 2024
Graylog vulnerable to instantiation of arbitrary classes triggered by API request
High8.8Feb 7, 2024
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low3.3Jul 6, 2023
Graylog vulnerable to insecure source port usage for DNS queries
Low3.7Jul 6, 2023
Graylog user session is still usable after logout
Low2.6Jul 6, 2023
Cross-site Scripting in Graylog
Medium6.1May 14, 2022
Cross-site Scripting in Graylog Server
Medium6.1May 14, 2022
Cross-site Scripting in Graylog Server
Medium6.1May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.