Rsyslog is a widely deployed open-source logging daemon and its associated libraries that handle syslog processing across servers and infrastructure, sitting deep in observability pipelines. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by the product's memory-management demands and its exposure through network-facing input handling and buffer-boundary operations. The recurring weakness classes—resource leaks, buffer overflows and out-of-bounds writes, and input-size validation gaps—are characteristic of C-based system software operating at the protocol parsing layer. Defenders should monitor this vendor's advisories for memory-safety disclosures affecting logging infrastructure; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rsyslog over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3200MEDIUM Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers t | Sep 6, 2011 | 5.0 | 38 | NO | YES |
CVE-2018-1000140CRITICAL rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This | Mar 23, 2018 | 9.8 | 35 | NO | NO |
CVE-2019-17041CRITICAL An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a l | Oct 7, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-17042CRITICAL An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message | Oct 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-17040CRITICAL contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled. | Sep 30, 2019 | 9.8 | 29 | NO | NO |
CVE-2022-24903HIGH Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a | May 6, 2022 | 8.1 | 28 | NO | NO |
CVE-2018-16881HIGH A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to c | Jan 25, 2019 | 7.5 | 26 | NO | NO |
CVE-2017-12588CRITICAL The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact. | Aug 6, 2017 | 9.8 | 25 | NO | NO |
CVE-2014-3634HIGH rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other | Nov 2, 2014 | 7.5 | 22 | NO | NO |
CVE-2008-5617HIGH The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and sp | Dec 17, 2008 | 8.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rsyslog.
Media articles that mention a CVE ID that affects a product developed by Rsyslog — matched by CVE ID, not by vendor name.