Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Cribl/
  3. Cribl Stream

Cribl Stream

PipelineAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 6 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~45 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Data pipeline for collecting, routing, and transforming telemetry data.

by Cribl · cribl.io · source ↗

Screenshots

1
Cribl Stream — screenshotauto

Known CVEs (6)2 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-56748 ↗HIGH 8.8new2026

    Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute a…

  • CVE-2026-56747 ↗HIGH 8.8new2026

    Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScrip…

  • CVE-2026-45393 ↗HIGH 7.82026

    A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges to NT AUTHORITY\SYSTEM. Incorrect default permissions on the Windows installer's …

  • CVE-2026-45392 ↗HIGH 8.72026

    DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a craft…

  • CVE-2026-45391 ↗HIGH 7.82026

    A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user to execute arbitrary commands in the context of the Cribl Edge service account.

  • CVE-2019-11076 ↗CRITICAL 9.82019

    Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other SIEM products

see all →
  • Abstract Security Platform · Abstract Security
  • AgileBlue Security Information and Event Management · AgileBlue
  • Anomali Unified Security Data Lake · Anomali
  • Anrita Cyber Defense · Zeronsec
  • Antiy Situational Awareness Platform · Antiy Labs
  • Auguria · Auguria
  • Autonomous Threat Sweeper · Securonix
  • Axoflow Platform · Axoflow