Path traversal in Fluentd - CVE-2026-44024
Published: June 29, 2026 / Updated: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to path traversal in the `${tag}` placeholder handling in file path configuration when processing log tags from untrusted sources. A remote attacker can inject path traversal sequences into a crafted tag to execute arbitrary code.
Exploitation requires the `${tag}` placeholder to be used in file-related configuration such as the `path` parameter, and certain formatting options can enable arbitrary file write or overwrite of existing files.
Affected software
openEuler
rubygem-fluentd
rubygem-fluentd-help
How to mitigate CVE-2026-44024
rubygem-fluentd - update to 1.16.2-2
rubygem-fluentd-help - update to 1.16.2-2