maven

org.graylog2:graylog2-server

View on maven registry
16 Total advisories
16 Vulnerabilities
0 Malware

Dependency scanning

Check whether org.graylog2:graylog2-server is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.3
Maven

CVE-2026-69190

Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards

HIGH 7.3
Maven

GHSA-q9q2-3ppx-mwqf

Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser

HIGH 8.8
Maven

CVE-2024-24824

Graylog vulnerable to instantiation of arbitrary classes triggered by API request

MEDIUM 5.7
Maven

CVE-2024-24823

Graylog session fixation vulnerability through cookie injection

LOW 2.6
Maven

CVE-2023-41041

Graylog user session is still usable after logout

LOW 3.3
Maven

CVE-2023-41044

Graylog server has partial path traversal vulnerability in Support Bundle feature

UNKNOWN
Maven

CVE-2026-55867

Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens

HIGH 7.5
Maven

CVE-2026-55841

Fortigate syslog message parser can be exploited to modify or delete fields from the original message

MEDIUM 5.0
Maven

CVE-2026-55425

Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields

UNKNOWN
Maven

CVE-2025-53106

Graylog vulnerable to privilege escalation through API tokens

HIGH 8.0
Maven

CVE-2025-46827

Graylog Allows Session Takeover via Insufficient HTML Sanitization

MEDIUM 6.5
Maven

CVE-2025-30373

Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value

LOW 3.7
Maven

CVE-2023-41045

Graylog vulnerable to insecure source port usage for DNS queries

MEDIUM 6.1
Maven

CVE-2018-14380

Cross-site Scripting in Graylog Server

MEDIUM 6.1
Maven

CVE-2018-11651

Cross-site Scripting in Graylog

MEDIUM 6.1
Maven

CVE-2018-11650

Cross-site Scripting in Graylog Server

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes