CVE-2026-44161 is a vulnerability in the Fluentd out_http output plugin that allows an attacker to control the destination hostname of outbound HTTP requests. This issue is fixed in version 1.19.3. The vulnerability has a high CVSS score of 7.2 and is classified as HIGH severity. Users of Fluentd out_http output plugin prior to version 1.19.3 should update to the latest version to prevent potential attack [truncated]
CVE-2026-44160 is a denial of service vulnerability in Fluentd's in_http and in_forward plugins. Prior to version 1.19.3, these plugins support gzip-compressed data but only enforce limits on compressed payloads. This allows crafted compressed payloads to decompress in memory to an excessive size, causing denial of service through memory exhaustion. The issue is fixed in version 1.19.3. Affected users sho [truncated]
Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API. Prior to version 1.19.3, responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3. The vulnerability has a high CVSS score of 7.5, indicati [truncated]
Fluentd, a data collector, has a critical vulnerability (CVE-2026-44024) allowing path traversal and potential remote code execution via untrusted tags. The issue is fixed in version 1.19.3. This vulnerability affects Fluentd users, particularly those using versions prior to 1.19.3, who should update to prevent potential remote code execution and data compromise. The vulnerability has a CVSS score of 9.8, [truncated]