CVE-2026-39879
Description
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8
How to fix CVE-2026-39879
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/syslog-ng—no fix listed
Is CVE-2026-39879 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-39879.
Affected packages (1)
- from 0