Improper handling of highly compressed data in Fluentd - #VU152735
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the streaming decompression path of Buffer::Chunk#open and #write_to when flushing compressed buffer chunks to an output IO or backup chunk. A remote attacker can supply highly compressible data to cause a denial of service.
Buffer compression must be enabled.