THREAT OPS › Threat News › [NVD] CVE-2026-19654 (HIGH 7.5) — A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege esc
[NVD] CVE-2026-19654 (HIGH 7.5) — A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege esc
CVE-2026-19654 CVSS: 7.5 HIGH Published: 2026-08-12T21:17:38.517
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp
Indicators of compromise
- CVE-2026-19654cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19654