GHSA-gqr6-r77p-c2pj: Fortigate syslog message parser can be exploited to modify or delete fields from the original message
Summary
Graylog has a vulnerability in its syslog message parser (a tool that reads and organizes log data) that allows attackers to modify or delete fields from log messages, particularly those from Fortigate devices. This can be exploited for log evasion, meaning attackers can hide their malicious activity by making logs appear invalid or incomplete.
Solution / Mitigation
Upgrade Graylog to version 6.3.12, 7.0.7, 7.1.2, or above. Graylog Cloud has already been patched automatically. For Enterprise or Security customers, check the Indexing and Processing Failures Index to find messages that may have been discarded due to parsing errors.
Vulnerability Details
EPSS: 0.0%
Yes
August 28, 2026
Classification
Affected Packages
Original source: https://github.com/advisories/GHSA-gqr6-r77p-c2pj
First tracked: August 28, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%