https://seclists.org/oss-sec/2026/q2/1004: CVE-2026-55556: rsyslog imhttp Basic Auth heap overflow
Published Jun 23, 2026
·Updated
Affected Software
1 affected component
rsyslog rsyslog imhttp<8.2604.0
Frequently Asked Questions
1
What is the severity of CVE-2026-55556?
CVE-2026-55556 has not been explicitly assigned a CVSS score, but it is classified as a heap overflow vulnerability which may allow for remote code execution.
2
How do I fix CVE-2026-55556?
To fix CVE-2026-55556, you should remove the optional rsyslog imhttp module if it is not in use or update to a patched version once it becomes available.
3
What software is affected by CVE-2026-55556?
CVE-2026-55556 affects the optional rsyslog imhttp input module, which is a contributed plugin for rsyslog installations.
4
Is CVE-2026-55556 common in production environments?
CVE-2026-55556 is not commonly found in production environments as the imhttp module is seldom installed.
5
When was CVE-2026-55556 published?
CVE-2026-55556 was published on June 23, 2026.