SB2026092923 - Multiple vulnerabilities in Fluentd



SB2026092923 - Multiple vulnerabilities in Fluentd

Published: September 29, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092923
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 75% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Improper handling of highly compressed data (CVE-ID: N/A)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in the streaming decompression path of Buffer::Chunk#open and #write_to when flushing compressed buffer chunks to an output IO or backup chunk. A remote attacker can supply highly compressible data to cause a denial of service.

Buffer compression must be enabled.


2) Improper handling of highly compressed data (CVE-ID: N/A)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in the `in_http` plugin's ndjson parsing logic when processing highly compressed ndjson HTTP payloads. A remote attacker can send a crafted payload containing millions of extremely short lines to exhaust memory and cause a denial of service.

The decompressed payload can pass the configured decompression size limit while allocation of individual string objects exhausts system memory.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the in_syslog TCP and TLS handlers when processing incomplete syslog message streams. A remote attacker can send a crafted unterminated stream or declare an incomplete oversized frame to cause a denial of service.

The issue affects TCP and TLS transports using traditional or octet-count framing.


4) Path traversal (CVE-ID: N/A)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to write arbitrary files or overwrite existing files with attacker-controlled content.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in output plugin file path template validation when substituting an untrusted bare `..` tag into a configured path template. A remote attacker can provide a bare `..` tag value to bypass directory restrictions and write arbitrary files or overwrite existing files with attacker-controlled content.

The secondary post-substitution validation is skipped when the buffer is configured to group by tag only.


Remediation

Install update from vendor's website.