Improper handling of highly compressed data in Fluentd - #VU152736

 

Improper handling of highly compressed data in Fluentd - #VU152736

Published: September 29, 2026


Vulnerability identifier: #VU152736
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-409
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in the `in_http` plugin's ndjson parsing logic when processing highly compressed ndjson HTTP payloads. A remote attacker can send a crafted payload containing millions of extremely short lines to exhaust memory and cause a denial of service.

The decompressed payload can pass the configured decompression size limit while allocation of individual string objects exhausts system memory.


Affected software

Fluentd

Remediation

Install security update from vendor's website.

Fluentd - update to 1.19.4

External References

Related Security Bulletins