Improper handling of highly compressed data in Fluentd - #VU152736
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the `in_http` plugin's ndjson parsing logic when processing highly compressed ndjson HTTP payloads. A remote attacker can send a crafted payload containing millions of extremely short lines to exhaust memory and cause a denial of service.
The decompressed payload can pass the configured decompression size limit while allocation of individual string objects exhausts system memory.