A vulnerability, which was classified as critical, has been found in rsyslog. Affected by this vulnerability is an unknown functionality of the component imhttp Basic Auth. Performing a manipulation results in heap-based buffer overflow.

This vulnerability is identified as CVE-2026-55556. The attack can be initiated remotely. There is not any exploit available.

Applying a patch is the recommended action to fix this issue.