CVE-2017-12588: Rsyslog

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.

Affected products

  • Rsyslog Rsyslog: up to and including 8.27.0

Published 2017-08-06. Last modified 2026-06-17.