Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Cribl Stream to v4.18.2 or higher. Upgrading fully resolves this vulnerability and no additional mitigation is required.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Jul 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cribl
Cribl cribl Stream |
|
| Vendors & Products |
Cribl
Cribl cribl Stream |
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack configuration value. | |
| Title | Code Injection in JSON Pointer Processing Component in Cribl Stream | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Cribl
Published:
Updated: 2026-07-27T20:23:09.438Z
Reserved: 2026-06-22T20:02:07.173Z
Link: CVE-2026-56747
Updated: 2026-07-27T20:23:06.347Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T00:45:02Z