Improper handling of highly compressed data in Fluentd - CVE-2026-44160
Published: June 29, 2026
Fluentd
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the `in_http` and `in_forward` plugins when processing gzip-compressed input. A remote attacker can send a maliciously crafted, highly compressed payload to cause a denial of service.
The issue can lead to memory exhaustion and an out-of-memory kill of the Fluentd process.