
CVE-2026-55556: rsyslog imhttp: Basic Auth heap overflow https://www.openwall.com/lists/oss-security/2026/06/23/4 requires - rsyslog built with the contributed imhttp module - imhttp installed and available - imhttp loaded and configured - HTTP Basic Authentication enabled - attacker access to that HTTP endpoint
Post summary
The post announces CVE‑2026‑55556, a heap overflow in rsyslog’s imhttp module when HTTP Basic Authentication is enabled, and specifies the conditions necessary for exploitation.

