CVE-2026-19654: Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

Published Jul 20, 2026
·
Updated

A configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd. The issue is not active in a default installation. Exploitation requires all of the following:

imptcp is explicitly loaded. An imptcp listener uses the non-default framing.delimiter.regex mode. An attacker can establish a TCP connection to that listener.

A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

Other sources

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

MITRE

Affected Software

1 affected component
rsyslog imptcp input module

Event History

Jul 20, 2026
Data Sourced
via Red Hat·04:58 PM
DescriptionSeverityAffected Software
Aug 12, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-19654?

CVE-2026-19654 has a severity rating of high, with a score of 7.5.

2

How do I fix CVE-2026-19654?

To fix CVE-2026-19654, it is recommended to apply the latest updates to the rsyslog software that address this vulnerability.

3

What impact does CVE-2026-19654 have on my system?

CVE-2026-19654 can cause rsyslogd to crash due to a crafted input sequence, but it does not affect confidentiality or integrity.

4

Is CVE-2026-19654 exploitable by authenticated users?

No, CVE-2026-19654 can be exploited by unauthenticated remote peers.

5

Which module is affected by CVE-2026-19654?

The vulnerability in CVE-2026-19654 specifically affects the optional imptcp input module of rsyslog.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203