Inefficient regular expression complexity in Fluentd - CVE-2021-41186
Published: October 29, 2021 / Updated: June 29, 2026
Fluentd
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in parser_apache2 when parsing broken apache log entries containing a certain string pattern. A remote attacker can supply a specially crafted log entry to cause a denial of service.