{"id":"CVE-2025-30373","summary":"Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value","details":"Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value the correct HTTP response (401) is returned, the message will be ingested nonetheless. To mitigate the vulnerability, disable http-based inputs and allow only authenticated pull-based inputs. This vulnerability is fixed in 6.1.9.","aliases":["GHSA-q7g5-jq6p-6wvx"],"modified":"2026-08-12T14:52:34.756330Z","published":"2025-04-07T14:37:58.071Z","database_specific":{"cwe_ids":["CWE-285"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30373.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30373.json"},{"type":"ADVISORY","url":"https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-q7g5-jq6p-6wvx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30373"},{"type":"FIX","url":"https://github.com/Graylog2/graylog2-server/commit/31bc13d3cd6f550ec83473d0f8666cd3ebf50f10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/graylog2/graylog2-server","events":[{"introduced":"cb28959341c6e8bde044718c0269f6155a9ecd66"},{"fixed":"bacfdef1fa5465f3ca6c23084789ad2c26b94c88"},{"fixed":"31bc13d3cd6f550ec83473d0f8666cd3ebf50f10"}],"database_specific":{"cpe":"cpe:2.3:a:graylog:graylog:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.1.0"},{"fixed":"6.1.9"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["6.1.8","6.1.7","6.1.6","6.1.5","6.1.4","6.1.3","6.1.2","6.1.1","6.1.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T14:52:34Z","vanir_signatures":[{"digest":{"line_hashes":["73762710035576621731727319515757412808","277496439535004060916283369720954642286","147037414169995217792047359184119972855","164468985165365917816312037916194742793","110293348433586239526624518794125616675","140357882704014329503713355978219624055","244281593647828825602480617433969487100","323551045665711814944222418996847483931"],"threshold":0.9},"id":"CVE-2025-30373-29804e22","signature_type":"Line","signature_version":"v1","source":"https://github.com/graylog2/graylog2-server/commit/31bc13d3cd6f550ec83473d0f8666cd3ebf50f10","target":{"file":"graylog2-server/src/test/java/org/graylog2/inputs/transports/netty/HttpHandlerTest.java"},"deprecated":false},{"target":{"file":"graylog2-server/src/test/java/org/graylog2/inputs/transports/netty/HttpHandlerTest.java","function":"testAuthentication"},"deprecated":false,"digest":{"function_hash":"153235275878334966024272324438715896248","length":1260},"id":"CVE-2025-30373-5a39d3e4","signature_type":"Function","signature_version":"v1","source":"https://github.com/graylog2/graylog2-server/commit/31bc13d3cd6f550ec83473d0f8666cd3ebf50f10"},{"signature_version":"v1","source":"https://github.com/graylog2/graylog2-server/commit/31bc13d3cd6f550ec83473d0f8666cd3ebf50f10","target":{"function":"channelRead0","file":"graylog2-server/src/main/java/org/graylog2/inputs/transports/netty/HttpHandler.java"},"deprecated":false,"digest":{"function_hash":"87855177674371145357816397446617497994","length":1245},"id":"CVE-2025-30373-703174bc","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["183201936823050678750267195370060821850","278300104164257450149503089910738777713","147739105711023657842500197578945997988","118033553782960855854576230332309108007"],"threshold":0.9},"id":"CVE-2025-30373-cdcdf2b9","signature_type":"Line","signature_version":"v1","source":"https://github.com/graylog2/graylog2-server/commit/31bc13d3cd6f550ec83473d0f8666cd3ebf50f10","target":{"file":"graylog2-server/src/main/java/org/graylog2/inputs/transports/netty/HttpHandler.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30373.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}