GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-681",
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55768.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55768.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "7186399750841121500367791321623152419",
"length": 328
},
"id": "CVE-2026-55768-3f101233",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5",
"target": {
"file": "src/websocket.c",
"function": "ws_realloc_frm_payload"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"72968566362850178300269376346680489484",
"289968415212257825840849053371240590075",
"213943987341781513548961245105007183047",
"239418607921541109711035770235692747219"
],
"threshold": 0.9
},
"id": "CVE-2026-55768-6e07c8c0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5",
"target": {
"file": "src/websocket.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "77846482677984869868676388125201215232",
"length": 1362
},
"id": "CVE-2026-55768-8a6753e5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5",
"target": {
"file": "src/websocket.c",
"function": "ws_get_frm_header"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"291697635191400429069637017194731479423",
"246433851209961756664872865185199574059",
"280628685390616385707598445997462597206",
"74569838204938262304612002467145103123",
"42673025952239434808026837863032877009",
"29048035309593467849159723649617147307",
"144667762103213679866831026184068838009",
"268910300533212774598564931024783089754"
],
"threshold": 0.9
},
"id": "CVE-2026-55768-921c010a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5",
"target": {
"file": "src/websocket.c"
}
}
]
"2026-09-10T08:13:48Z"