- Package:
- src:goaccess
- Source:
- src:goaccess
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-05 17:35:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for goaccess. CVE-2026-54715[0]: | GoAccess is a real-time web log analyzer and interactive viewer that | runs in a terminal in *nix systems or through the browser. In | version 1.10.2, parse_browser assumes the matched browser token | begins with Opera and moves a trailing version substring to match | plus five, allowing a crafted User-Agent in a processed access log | to write one to four attacker-influenced bytes beyond the heap | allocation and corrupt or crash GoAccess. This issue is fixed in | version 1.11. CVE-2026-55768[1]: | GoAccess is a real-time web log analyzer and interactive viewer that | runs in a terminal in *nix systems or through the browser. Prior to | version 1.11, the built-in WebSocket server narrows a 64-bit | extended frame length into the signed 32-bit WSFrame.payloadlen | field before enforcing the maximum frame size, allowing an | unauthenticated remote client to bypass the guard and force an | approximately 18-exabyte allocation request that terminates the | process. This issue is fixed in version 1.11. CVE-2026-55777[2]: | GoAccess is a real-time web log analyzer and interactive viewer that | runs in a terminal in *nix systems or through the browser. Prior to | 1.11, the parse_ios() function uses an attacker-controlled keyword- | to-OS offset as both the source offset and copy length for memmove, | allowing a crafted User-Agent in a processed access log to read up | to approximately 4 KB beyond the heap allocation and conditionally | crash GoAccess. This issue is fixed in version 1.11. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54715 https://www.cve.org/CVERecord?id=CVE-2026-54715 [1] https://security-tracker.debian.org/tracker/CVE-2026-55768 https://www.cve.org/CVERecord?id=CVE-2026-55768 [2] https://security-tracker.debian.org/tracker/CVE-2026-55777 https://www.cve.org/CVERecord?id=CVE-2026-55777 Regards, Salvatore
I just uploaded a new upstream release that includes the fixes for these to unstable. I also have a trixie branch where I cherry picked the individual fixes. I'm attaching the full diff and the individual patches here, LMK what you think. Are you releasing a DSA for those, or should I go for a stable update?
We believe that the bug you reported is fixed in the latest version of
goaccess, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143181@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Antonio Terceiro <terceiro@debian.org> (supplier of updated goaccess package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 17 Aug 2026 18:51:32 -0300
Source: goaccess
Architecture: source
Version: 1:1.11-1
Distribution: unstable
Urgency: medium
Maintainer: Antonio Terceiro <terceiro@debian.org>
Changed-By: Antonio Terceiro <terceiro@debian.org>
Closes: 1143181
Changes:
goaccess (1:1.11-1) unstable; urgency=medium
.
* New upstream release. Includes fixes for the following security
vulnerabilities (Closes: #1143181)
- CVE-2026-54715: Heap Out-of-Bounds Write in GoAccess `parse_browser()`
- CVE-2026-55768: GoAccess WebSocket server: signed 32 bit truncation of
the 64 bit frame length causes a remote pre authentication denial of
service
- CVE-2026-55777: Out-of-bounds heap read in parse_ios() via crafted
User-Agent (opesys.c:323) lead to remote crash/DoS
Checksums-Sha1:
9c34feacd2161d607b6bec09c2ec6aec2950b51c 2302 goaccess_1.11-1.dsc
844a56abd75eae4a6ac3e39b79526c0747d83d96 671456 goaccess_1.11.orig.tar.xz
49a8c6c155bbc3878fcf6e6bc9d70b664db0bff4 155896 goaccess_1.11-1.debian.tar.xz
97c77a5eae623b75e1f0d8ec5696366b6ccf042b 1707872 goaccess_1.11-1.git.tar.xz
d59cc751f7520685413c75f0571a0d5350479781 17554 goaccess_1.11-1_source.buildinfo
Checksums-Sha256:
5cfdc6132d6cf16d92db8227c74fbe6e7b44b090c4ae96dca5d74aeeb5ab040f 2302 goaccess_1.11-1.dsc
64bdb663702072c1fcd54df86d04607b0fc3b44c39ef5f03ac30ed851cb7db17 671456 goaccess_1.11.orig.tar.xz
e9c9e9f87f700edeeabcd66d550500396237c20be544dd74bc4c15b402ee71e6 155896 goaccess_1.11-1.debian.tar.xz
6d15e27be2c52866329135db4e7dc2f3d903a74f0aba2139504e6de060693aaa 1707872 goaccess_1.11-1.git.tar.xz
374eea9a9bb849eca108e8ff589cffab8ffab85061694e7eaf7ed769efca0142 17554 goaccess_1.11-1_source.buildinfo
Files:
eb3a0c27e642058f9c67ccd66f370d58 2302 utils optional goaccess_1.11-1.dsc
adcc5a5c85d156c60266dd29e2513255 671456 utils optional goaccess_1.11.orig.tar.xz
a5f67145d8c46500910a3fb2bc4db696 155896 utils optional goaccess_1.11-1.debian.tar.xz
948f24d294fc93e34f04f3c722614565 1707872 utils optional goaccess_1.11-1.git.tar.xz
1f01f0d3e5b40a4bde3f6af5bd002a5c 17554 utils optional goaccess_1.11-1_source.buildinfo
Git-Tag-Info: tag=b7bec9f508d71097f8a8bedeccc4c5f9e838bdcc fp=b2dee66036c40829fcd0f10cfc0db1bbcd460bde
Git-Tag-Tagger: Antonio Terceiro <terceiro@debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqDgu4ACgkQYG0ITkaD
wHmycRAAn5Jz9llcxLExw41ZmfXiaY4WyYCtSYlfh0G5RgkJfWqE6Bs8PlbbgxkO
Z58H0A4O2E9mx7KxCGMoqTe0Az8duazpQQdoCjGo4/UUm3q8438WrnpzAiRc9yol
3CabVb1I/Mx3Q8TYZ6U2yCfQSRiP0ADcJA2gQKoeqd0re0WqyyuGPuyOCOCiqCIA
t9d+HBD0SNR17kEfAWZAdFLINvaZhk+X3ZmjE0yAr038hpyltnS84PFhUVSCjeCG
PsvYCPWDowM11la1cMCUAZvULxvfWm96rmHpStndZxa2q9kB9NucZEC/CEfhHU3V
UksJxvM5liw2PiyJnMQCdHP+ywKjua5/TxTC99Jba24+7vjt1/3fQSQu1opP3tan
r+G8mpn0xF2/j5x2e1N5PC2F8A7LbHz/6snymLp/ZFPmLV2UQeygKFouEOVcKD7w
2TPdWRFf4kDcRNKvD9lCVGgPRBwx6lgCJiweZhcYcg2JS5UJHlI9akY6T6+pjelw
Wov4DndsWEoAtPwg/MRaUmcqIVVM/e1Qyt5y1ikDxcqu916VPuB0ZLDsW2DCCaAp
LeyicbDPB+aPFfEL8IapU4nAq+JwQbjCIxMz3LeJsBSaRnmmtgSM0MoqHgk+PkUn
RL6oo9C6shRPwUtxOamRoXM9DnHyr0h+3/HEHAtWHZaSB4s+M2s=
=wf7+
-----END PGP SIGNATURE-----
Hi Antonio, Thank you very much, updating the metadata on our end. I think a point release update would be enough here, we did already mark the issues no-dsa in the tracker. Thanks for your work! Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
goaccess, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143181@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Antonio Terceiro <terceiro@debian.org> (supplier of updated goaccess package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 17 Aug 2026 18:49:23 -0300
Source: goaccess
Architecture: source
Version: 1:1.9.3-1+deb13u1
Distribution: trixie
Urgency: high
Maintainer: Antonio Terceiro <terceiro@debian.org>
Changed-By: Antonio Terceiro <terceiro@debian.org>
Closes: 1143181
Changes:
goaccess (1:1.9.3-1+deb13u1) trixie; urgency=high
.
* Apply security updates (Closes: #1143181)
Includes fixes for the following vulnerabilities:
- CVE-2026-54715: Heap Out-of-Bounds Write in GoAccess `parse_browser()`
- CVE-2026-55768: GoAccess WebSocket server: signed 32 bit truncation of
the 64 bit frame length causes a remote pre authentication denial of
service
- CVE-2026-55777: Out-of-bounds heap read in parse_ios() via crafted
User-Agent (opesys.c:323) lead to remote crash/DoS
* debian/salsa-ci.yml: disable uscan test for this branch
Checksums-Sha1:
4b2fb2367e02e4c08e7afe4e0f5d2836c56790ca 2023 goaccess_1.9.3-1+deb13u1.dsc
f35aa15e7f9b7642168868d34684532d2929c808 156964 goaccess_1.9.3-1+deb13u1.debian.tar.xz
abb33d319453831068c77e71e30061a4888b83f2 6574 goaccess_1.9.3-1+deb13u1_source.buildinfo
Checksums-Sha256:
9bb9db61ebc19f06eb89b2cc4f60a23427a4bbd0174896f9461767a99426ab87 2023 goaccess_1.9.3-1+deb13u1.dsc
2f477a3b3a06efae29680e649ae68c76db479eeccbd22a05f8c895d356e28710 156964 goaccess_1.9.3-1+deb13u1.debian.tar.xz
866b3567aafd691e49eb4d32bc617f1b01f5f50c688a9c9394e1c2097df9363d 6574 goaccess_1.9.3-1+deb13u1_source.buildinfo
Files:
c1c81ee4ab4e0ac262c715482f6e20ae 2023 utils optional goaccess_1.9.3-1+deb13u1.dsc
ebed69f90b620dffb87d50e00bf6b910 156964 utils optional goaccess_1.9.3-1+deb13u1.debian.tar.xz
01430c91e8bbd9cb16213f5f4f5f7f6b 6574 utils optional goaccess_1.9.3-1+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEst7mYDbECCn80PEM/A2xu81GC94FAmqcKuMACgkQ/A2xu81G
C94P2g/+J9IKaLmtoMGydXihczwUpMjkdMWYVI3adfHfbGVrqg6yp5NApWTUHIaI
NMpVdIy6uIoHJnW5y5ChS47kcchmJpLwee9iAtkrBZLI2yuEP8UiuIVUfjU1ZA7/
GsXyk4VpyoyleZtldzgiTM/n7HZZmnvrdLxMa5DFOFSX0Z76xc9HDXiBoA+SEbW9
lkc3H+kViaKK8TdkONHix6dVU/0Z5zKRgv6lizj8Me3DzS8QjTaoW1fmTWG7wtTi
Sj8zWECU2wCWs+7Aa1ei96Ex38Pxff1X9/+vzlwL3tk4V5c199FX3mL5OTUm2MXx
QbEGgPcsbF8lCdNTyAhNjWEIeQXX1iFN6YcKI3li3nxv9gZmYDASUXBMwhOTQ70C
rRdt7ulk9zr6HNhQNju+xIoMXpfzIJpf087UxtOYEIpge0Dsqwmz1kx47n0xUxDb
uxHqUAXZwuYu9hwIsGF/39sgfkZxei4V2MgKzY5iL69K0/aXniY7r1aFvXJjqL7F
5Kcxtj5kPHQPEb3ybdjcztaGcGL8bWx1wOcg7KyLY0iavQc9YvRG1Gn6A+6Ap3u4
Rt+lHWNMsi3cyLIlF9OIqXZ0dfFWyr/MRp8+BQEJJoArx1IXbTS2x0NOTiTOwyqq
CVSr1YBg/DD5A/n++d6va/CuHEr671mJ37T2zY4VK7eAVA8VVQ0=
=K1Vh
-----END PGP SIGNATURE-----