Allocation of Resources Without Limits or Throttling in Fluentd - #VU152737
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the in_syslog TCP and TLS handlers when processing incomplete syslog message streams. A remote attacker can send a crafted unterminated stream or declare an incomplete oversized frame to cause a denial of service.
The issue affects TCP and TLS transports using traditional or octet-count framing.