syslog-ng SQL Injection Vulnerability in AFSQl Destination Driver

Vulnerability

A SQL injection vulnerability has been identified in syslog-ng versions prior to 4.12, as well as in syslog-ng Premium Edition versions prior to 8.2 and syslog-ng Store Box versions prior to 7.8. The issue arises from a missing sanitization call in the AFSQl destination driver, allowing untrusted sources to inject malicious SQL. This vulnerability is not part of the default configuration and requires the SQL driver to be manually enabled.

Impact

Exploitation of this vulnerability could lead to SQL injection, allowing attackers to manipulate SQL queries and potentially access or modify database information.

Remediation

Users can update to syslog-ng 4.12, syslog-ng Premium Edition 8.2, or syslog-ng Store Box 7.8 to address this vulnerability. If the SQL driver is used, implement server-side query sanitization as an additional precaution.

Added: Jul 20, 2026, 6:23 PM
Updated: Jul 20, 2026, 6:23 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
7.8
remediation
8.3
relevance
9.9
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.