Back Linuxsecurity Fedora 43 GoAccess 1.11 Important Buffer Overflow Fix 2026
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
GoAccess is a real-time web log analyzer and interactive viewer that runs in a
terminal in *nix systems. It provides fast and valuable HTTP statistics for
system administrators that require a visual server report on the fly.
GoAccess parses the specified web log file and outputs the data to terminal.
* General statistics, bandwidth, etc.
* Time taken to serve the request (useful to track pages that are slowing down
* Metrics for cumulative, average and slowest running requests.
* Requested files & static files.
* Hosts, Reverse DNS, IP Location.
* Browsers and Spiders.
* Referring Sites & URLs.
* Geo Location - Continent/Country/City.
* Visitors Time Distribution.
* Ability to output JSON and CSV.
* Tailor GoAccess to suit your own color taste/schemes.
* Support for large datasets + data persistence.
* Output statistics to HTML.
GoAccess allows any custom log format string. Predefined options include, but
* Amazon CloudFront (Download Distribution).
* AWS Elastic Load Balancing.
* Apache/Nginx Common/Combined + VHosts.
Update to goaccess 1.11. Notable fixes: - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed unique visitor undercounting caused by key collisions - Fixed city lookups ignoring the City database when Country was listed first Also includes: automatic crash-safe migration to storage format v3, ~20% lower storage memory usage and ~35% faster parsing, fullscreen geolocation map controls in the HTML report, and Traditional Chinese translation.
* Sat Jul 25 2026 Eduardo Echeverria - 1.11-1 - Update to 1.11. Fixes rhbz#2502800 - Added automatic, crash-safe migration of persisted databases to storage format version 3 - Added configured zlib and AddressSanitizer options to the version output - Added fullscreen expand and collapse controls to geolocation maps in the HTML report - Added Traditional Chinese translation - Expanded Debian package builds to Ubuntu 26.04 and additional architectures, and updated the packaging workflow actions - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed city lookups ignoring the City database when a Country database was listed first - Fixed geolocation maps appearing grey after restoring persisted city data - Fixed .gz file extensions being interpreted as macros in the man page - Fixed iOS version parsing from user-agent strings - Fixed unique visitor undercounting caused by collisions between reversed data and visitor key pairs - Fixed WebSocket payload size checks for large and fragmented messages - Grouped Lynx, Links, ELinks, w3m and Chawan under a new "Text-based" browser category - Reduced storage memory usage by 20% and parsing time by 35%
* Sat Jul 25 2026 Eduardo Echeverria - 1.11-1 - Update to 1.11. Fixes rhbz#2502800 - Added automatic, crash-safe migration of persisted databases to storage format version 3 - Added configured zlib and AddressSanitizer options to the version output - Added fullscreen expand and collapse controls to geolocation maps in the HTML report - Added Traditional Chinese translation - Expanded Debian package builds to Ubuntu 26.04 and additional architectures, and updated the packaging workflow actions - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed city lookups ignoring the City database when a Country database was listed first - Fixed geolocation maps appearing grey after restoring persisted city data - Fixed .gz file extensions being interpreted as macros in the man page - Fixed iOS version parsing from user-agent strings - Fixed unique visitor undercounting caused by collisions between reversed data and visitor key pairs - Fixed WebSocket payload size checks for large and fragmented messages - Grouped Lynx, Links, ELinks, w3m and Chawan under a new "Text-based" browser category - Reduced storage memory usage by 20% and parsing time by 35%
[ 1 ] Bug #2502800 - goaccess-1.11 is available
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a488a993d1' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
