← Vulnerability feed

Vulnerability record · CVE-2026-44160 · published 8 July 2026

CVE-2026-44160: Fluentd vulnerability

Fluentd · Fluentd

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.

7.5 CVSS 3.1 High EPSS 0.62% · top 52.4% CWE-409 · CWE-409
7.5CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
13 Jul 2026Last modified by NVD

Description

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44160 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-44024Fluentd path traversal vulnerabilityFluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allo…EPSS 1.1%9.8CVE-2022-39379Fluentd unauthenticated RCE via unsafe JSON deserializationFluentd, when the non-default environment variable FLUENT_OJ_OPTION_MODE is set to object, deserializes untrusted JSON payloads unsafely, allowing re…EPSS 45%analysed9.8CVE-2017-10906Fluentd vulnerabilityEscape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitr…EPSS 4.6%8.8CVE-2020-21514Fluentd incorrect default permissions vulnerabilityAn issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.EPSS 0.79%7.5CVE-2026-44025Fluentd missing authentication for critical function vulnerabilityFluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Mo…EPSS 0.47%7.5CVE-2021-41186Fluentd uncontrolled resource consumption vulnerabilityFluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd…EPSS 2.2%7.2CVE-2026-44161Fluentd server-side request forgery (ssrf) vulnerabilityFluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd …EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2026-44160), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.