Server-Side Request Forgery (SSRF) in Fluentd - CVE-2026-44161
Published: June 29, 2026
Fluentd
Detailed vulnerability description
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to server-side request forgery in the out_http endpoint configuration parameter when expanding placeholders derived from untrusted user input. A remote attacker can supply a crafted placeholder value to perform server-side request forgery.
This can cause outbound HTTP requests to be sent to internal services or cloud metadata endpoints.