CVE-2026-54511: @logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
@logtape/syslog contains two related output-encoding bugs in the structured data formatting code. Both only affect deployments with includeStructuredData: true, which is non-default.
References
- github.com/advisories/GHSA-8h6h-x5pq-56fq
- github.com/dahlia/logtape/commit/7a6e5b9ddf7915edfff78fa129bc17c979b2a623
- github.com/dahlia/logtape/releases/tag/1.3.11
- github.com/dahlia/logtape/releases/tag/2.0.14
- github.com/dahlia/logtape/releases/tag/2.1.5
- github.com/dahlia/logtape/security/advisories/GHSA-8h6h-x5pq-56fq
- nvd.nist.gov/vuln/detail/CVE-2026-54511
Code Behaviors & Features
Detect and mitigate CVE-2026-54511 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →