#1143181 goaccess: CVE-2026-54715 CVE-2026-55768 CVE-2026-55777

Package:
src:goaccess
Source:
src:goaccess
Submitter:
Salvatore Bonaccorso
Date:
2026-08-18 05:01:01 UTC
Severity:
normal
Tags:
#1143181#5
Date:
2026-07-31 12:31:52 UTC
From:
To:
Hi,

The following vulnerabilities were published for goaccess.

CVE-2026-54715[0]:
| GoAccess is a real-time web log analyzer and interactive viewer that
| runs in a terminal in *nix systems or through the browser. In
| version 1.10.2, parse_browser assumes the matched browser token
| begins with Opera and moves a trailing version substring to match
| plus five, allowing a crafted User-Agent in a processed access log
| to write one to four attacker-influenced bytes beyond the heap
| allocation and corrupt or crash GoAccess. This issue is fixed in
| version 1.11.


CVE-2026-55768[1]:
| GoAccess is a real-time web log analyzer and interactive viewer that
| runs in a terminal in *nix systems or through the browser. Prior to
| version 1.11, the built-in WebSocket server narrows a 64-bit
| extended frame length into the signed 32-bit WSFrame.payloadlen
| field before enforcing the maximum frame size, allowing an
| unauthenticated remote client to bypass the guard and force an
| approximately 18-exabyte allocation request that terminates the
| process. This issue is fixed in version 1.11.


CVE-2026-55777[2]:
| GoAccess is a real-time web log analyzer and interactive viewer that
| runs in a terminal in *nix systems or through the browser. Prior to
| 1.11, the parse_ios() function uses an attacker-controlled keyword-
| to-OS offset as both the source offset and copy length for memmove,
| allowing a crafted User-Agent in a processed access log to read up
| to approximately 4 KB beyond the heap allocation and conditionally
| crash GoAccess. This issue is fixed in version 1.11.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54715
https://www.cve.org/CVERecord?id=CVE-2026-54715
[1] https://security-tracker.debian.org/tracker/CVE-2026-55768
https://www.cve.org/CVERecord?id=CVE-2026-55768
[2] https://security-tracker.debian.org/tracker/CVE-2026-55777
https://www.cve.org/CVERecord?id=CVE-2026-55777

Regards,
Salvatore

#1143181#10
Date:
2026-08-17 21:55:54 UTC
From:
To:
I just uploaded a new upstream release that includes the fixes for these
to unstable.

I also have a trixie branch where I cherry picked the individual fixes.
I'm attaching the full diff and the individual patches here, LMK what
you think. Are you releasing a DSA for those, or should I go for a
stable update?

#1143181#15
Date:
2026-08-17 22:05:06 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
goaccess, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143181@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Antonio Terceiro <terceiro@debian.org> (supplier of updated goaccess package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 17 Aug 2026 18:51:32 -0300
Source: goaccess
Architecture: source
Version: 1:1.11-1
Distribution: unstable
Urgency: medium
Maintainer: Antonio Terceiro <terceiro@debian.org>
Changed-By: Antonio Terceiro <terceiro@debian.org>
Closes: 1143181
Changes:
 goaccess (1:1.11-1) unstable; urgency=medium
 .
   * New upstream release. Includes fixes for the following security
     vulnerabilities (Closes: #1143181)
     - CVE-2026-54715: Heap Out-of-Bounds Write in GoAccess `parse_browser()`
     - CVE-2026-55768: GoAccess WebSocket server: signed 32 bit truncation of
       the 64 bit frame length causes a remote pre authentication denial of
       service
     - CVE-2026-55777: Out-of-bounds heap read in parse_ios() via crafted
       User-Agent (opesys.c:323) lead to remote crash/DoS
Checksums-Sha1:
 9c34feacd2161d607b6bec09c2ec6aec2950b51c 2302 goaccess_1.11-1.dsc
 844a56abd75eae4a6ac3e39b79526c0747d83d96 671456 goaccess_1.11.orig.tar.xz
 49a8c6c155bbc3878fcf6e6bc9d70b664db0bff4 155896 goaccess_1.11-1.debian.tar.xz
 97c77a5eae623b75e1f0d8ec5696366b6ccf042b 1707872 goaccess_1.11-1.git.tar.xz
 d59cc751f7520685413c75f0571a0d5350479781 17554 goaccess_1.11-1_source.buildinfo
Checksums-Sha256:
 5cfdc6132d6cf16d92db8227c74fbe6e7b44b090c4ae96dca5d74aeeb5ab040f 2302 goaccess_1.11-1.dsc
 64bdb663702072c1fcd54df86d04607b0fc3b44c39ef5f03ac30ed851cb7db17 671456 goaccess_1.11.orig.tar.xz
 e9c9e9f87f700edeeabcd66d550500396237c20be544dd74bc4c15b402ee71e6 155896 goaccess_1.11-1.debian.tar.xz
 6d15e27be2c52866329135db4e7dc2f3d903a74f0aba2139504e6de060693aaa 1707872 goaccess_1.11-1.git.tar.xz
 374eea9a9bb849eca108e8ff589cffab8ffab85061694e7eaf7ed769efca0142 17554 goaccess_1.11-1_source.buildinfo
Files:
 eb3a0c27e642058f9c67ccd66f370d58 2302 utils optional goaccess_1.11-1.dsc
 adcc5a5c85d156c60266dd29e2513255 671456 utils optional goaccess_1.11.orig.tar.xz
 a5f67145d8c46500910a3fb2bc4db696 155896 utils optional goaccess_1.11-1.debian.tar.xz
 948f24d294fc93e34f04f3c722614565 1707872 utils optional goaccess_1.11-1.git.tar.xz
 1f01f0d3e5b40a4bde3f6af5bd002a5c 17554 utils optional goaccess_1.11-1_source.buildinfo
Git-Tag-Info: tag=b7bec9f508d71097f8a8bedeccc4c5f9e838bdcc fp=b2dee66036c40829fcd0f10cfc0db1bbcd460bde
Git-Tag-Tagger: Antonio Terceiro <terceiro@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqDgu4ACgkQYG0ITkaD
wHmycRAAn5Jz9llcxLExw41ZmfXiaY4WyYCtSYlfh0G5RgkJfWqE6Bs8PlbbgxkO
Z58H0A4O2E9mx7KxCGMoqTe0Az8duazpQQdoCjGo4/UUm3q8438WrnpzAiRc9yol
3CabVb1I/Mx3Q8TYZ6U2yCfQSRiP0ADcJA2gQKoeqd0re0WqyyuGPuyOCOCiqCIA
t9d+HBD0SNR17kEfAWZAdFLINvaZhk+X3ZmjE0yAr038hpyltnS84PFhUVSCjeCG
PsvYCPWDowM11la1cMCUAZvULxvfWm96rmHpStndZxa2q9kB9NucZEC/CEfhHU3V
UksJxvM5liw2PiyJnMQCdHP+ywKjua5/TxTC99Jba24+7vjt1/3fQSQu1opP3tan
r+G8mpn0xF2/j5x2e1N5PC2F8A7LbHz/6snymLp/ZFPmLV2UQeygKFouEOVcKD7w
2TPdWRFf4kDcRNKvD9lCVGgPRBwx6lgCJiweZhcYcg2JS5UJHlI9akY6T6+pjelw
Wov4DndsWEoAtPwg/MRaUmcqIVVM/e1Qyt5y1ikDxcqu916VPuB0ZLDsW2DCCaAp
LeyicbDPB+aPFfEL8IapU4nAq+JwQbjCIxMz3LeJsBSaRnmmtgSM0MoqHgk+PkUn
RL6oo9C6shRPwUtxOamRoXM9DnHyr0h+3/HEHAtWHZaSB4s+M2s=
=wf7+
-----END PGP SIGNATURE-----

#1143181#20
Date:
2026-08-18 04:58:12 UTC
From:
To:
Hi Antonio,

Thank you very much, updating the metadata on our end.

I think a point release update would be enough here, we did already
mark the issues no-dsa in the tracker.

Thanks for your work!

Regards,
Salvatore