fluentd
Fluentd is an open source data collector designed to scale and simplify log management. It can collect, process and ship many kinds of data in near real-time.
Activity
- Latest release
- 2mo ago
- Total releases
- 243
- Cadence
- ~33 days
- Last 12 months
- 4
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Oct 15, 2011
| Version | Released | |
|---|---|---|
1.19.3
patch
|
1.19.3
patch
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
1.19.2
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.19.2
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.16.11
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.11
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
1.19.1
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.19.1
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
1.16.10
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.10
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
1.19.0
minor
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.19.0
minor
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.16.9
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.9
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
1.16.8
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.8
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
1.16.7
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.7
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
1.18.0
minor
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.18.0
minor
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
1.16.6
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.6
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.17.1
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.17.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
1.17.0
minor
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.17.0
minor
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
1.16.5
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.5
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.16.4
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.4
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.16.3
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.3
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.16.2
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.2
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.16.1
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.1
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.16.0
minor
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.16.0
minor
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.15.3
patch
4 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev |
1.15.3
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.15.2
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.15.2
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.15.1
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.15.1
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
1.15.0
minor
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.15.0
minor
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
1.14.6
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.14.6
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
1.14.5
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.14.5
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
1.14.4
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.14.4
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.14.3
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.14.3
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.14.2
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev |
1.14.2
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.14.1
patch
6 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.14.1
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.14.0
minor
6 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.14.0
minor
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.14.0.rc
pre
6 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.14.0.rc
pre
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.13.3
patch
6 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.13.3
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.13.2
patch
6 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39379
GHSA-fppq-mj76-fpj2
BIT-fluentd-2022-39379
Nov 02, 2022
fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactA remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. Patchesv1.15.3 WorkaroundsDo not use References
Affected versions
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
+ 1 more Show less
1.15.2
Fixed in
1.15.3
References
Updated Feb 21, 2024 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.13.2
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.13.1
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.13.1
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.13.0
minor
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.13.0
minor
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.12.4
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.4
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.12.3
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.3
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.12.2
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.2
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.12.1
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.1
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.12.0
minor
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.0
minor
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.12.0.rc2
pre
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.0.rc2
pre
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.12.0.rc1
pre
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.12.0.rc1
pre
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.11.5
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.11.5
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.11.4
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.11.4
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.11.3
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.11.3
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.11.2
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.11.2
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.11.1
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.11.1
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.11.0
minor
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.11.0
minor
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.10.4
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.10.4
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
1.10.3
patch
5 CVEs
CVE-2026-44161
GHSA-72f5-rr8c-r6gr
BIT-fluentd-2026-44161
Jun 26, 2026
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
7.2
/ 10
High
Network
Low
None
None
Changed
Low
None
Low
The ImpactThis vulnerability allows for a Server-Side Request Forgery (SSRF) attack.
An unauthenticated attacker can force the Fluentd node to send HTTP requests to arbitrary internal services. This can lead to unauthorized access to internal APIs, data exfiltration, or the compromise of cloud metadata endpoints (e.g., AWS IMDS Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44160
GHSA-j9cw-hwqf-85w7
BIT-fluentd-2026-44160
Jun 26, 2026
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Fluentd's If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits. ImpactThis vulnerability allows for a Denial of Service (DoS) attack via memory exhaustion. The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system. This results in the disruption of all log collection and forwarding capabilities on the affected node. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44025
GHSA-pr7j-96cj-549h
BIT-fluentd-2026-44025
Jun 26, 2026
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Fluentd's Monitor Agent plugin ( If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API. ImpactThis vulnerability allows for unauthorized information disclosure. An attacker who can reach the Monitor Agent API port (default: Patches:v1.19.3 WorkaroundsIf usesrs cannot immediately update Fluentd to the patched version, they can mitigate this risk by strictly controlling access to the Monitor Agent port. Ensure the Monitor Agent is only bound to
Use firewall rules (e.g., iptables, AWS Security Groups) to block access to the Monitor Agent port ( Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44024
GHSA-44hj-4m45-frj3
BIT-fluentd-2026-44024
Jun 26, 2026
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Fluentd allows dynamically constructing file paths using the If a Fluentd instance is configured to receive logs from untrusted sources and uses the When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions. ImpactThis vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process. Patchesv1.19.3 WorkaroundsIf an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.15
0.10.16
0.10.17
0.10.18
0.10.19
0.10.2
+ 230 more Show less
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.36
0.10.37
0.10.38
0.10.39
0.10.4
0.10.40
0.10.41
0.10.42
0.10.43
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.49
0.10.5
0.10.50
0.10.51
0.10.52
0.10.53
0.10.54
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.6
0.10.60
0.10.61
0.10.62
0.10.7
0.10.8
0.10.9
0.12.0
0.12.0.pre.1
0.12.0.pre.2
0.12.0.pre.3
0.12.1
0.12.10
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.24
0.12.25
0.12.26
0.12.27
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.34
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.14.0
0.14.1
0.14.10
0.14.11
0.14.12
0.14.13
0.14.14
0.14.14.pre.1
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.2
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
0.14.23
0.14.23.rc1
0.14.24
0.14.25
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.14.2
1.14.3
1.14.4
1.14.5
1.14.6
1.15.0
1.15.1
1.15.2
1.15.3
1.16.0
1.16.1
1.16.10
1.16.11
1.16.2
1.16.3
1.16.4
1.16.5
1.16.6
1.16.7
1.16.8
1.16.9
1.17.0
1.17.1
1.18.0
1.19.0
1.19.1
1.19.2
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.19.3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-41186
GHSA-hwhf-64mh-r662
BIT-fluentd-2021-41186
Nov 01, 2021
ReDoS vulnerability in parser_apache2
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Impactparser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. Patchesv1.14.2 WorkaroundsEither of the following:
References
Affected versions
0.14.14
0.14.15
0.14.16
0.14.17
0.14.18
0.14.19
0.14.20
0.14.20.rc1
0.14.21
0.14.22
0.14.22.rc1
0.14.22.rc2
+ 79 more Show less
0.14.23
0.14.23.rc1
0.14.24
0.14.25
1.0.0
1.0.0.rc1
1.0.1
1.0.2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.12.0
1.12.0.rc1
1.12.0.rc2
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
1.14.0.rc
1.14.1
1.2.0
1.2.0.pre1
1.2.1
1.2.2
1.2.3
1.2.4
1.2.4.rc1
1.2.5
1.2.5.rc1
1.2.6
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.0.rc1
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.0.rc1
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0.rc1
1.8.0.rc2
1.8.0.rc3
1.8.1
1.9.0
1.9.0.rc1
1.9.0.rc2
1.9.1
1.9.2
1.9.3
Fixed in
1.14.2
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.10.3
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|