GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed access log to read up to approximately 4 KB beyond the heap allocation and conditionally crash GoAccess. This issue is fixed in version 1.11.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55777.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55777.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "259694106751180817752874489220024316186",
"length": 427
},
"id": "CVE-2026-55777-9ee483e9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81",
"target": {
"file": "src/opesys.c",
"function": "parse_ios"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"262058444158249902851174790630391218748",
"317085133410112339331123141436377758688",
"77432167615781091938045883110615317906",
"18815247221543410513439915825559918934"
],
"threshold": 0.9
},
"id": "CVE-2026-55777-d1674b5f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81",
"target": {
"file": "src/opesys.c"
}
}
]
"2026-09-10T08:13:07Z"