Description
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m
Scores
CVSS v3
7.1
EPSS
0.0017
EPSS Percentile
6.8%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-150
Status
published
Products (1)
syslog-ng/syslog-ng
< 4.12
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026