Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.
References
| Link | Resource |
|---|---|
| https://github.com/fluent/fluentd/commit/f5f2b7cddf8aab3932e6dec9fa367a5f3eb27e10 | Patch |
| https://github.com/fluent/fluentd/pull/5393 | Issue Tracking Patch |
| https://github.com/fluent/fluentd/releases/tag/v1.19.3 | Product Release Notes |
| https://github.com/fluent/fluentd/security/advisories/GHSA-j9cw-hwqf-85w7 | Mitigation Vendor Advisory |
Configurations
History
13 Jul 2026, 18:48
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fluentd
Fluentd fluentd |
|
| CPE | cpe:2.3:a:fluentd:fluentd:*:*:*:*:*:*:*:* | |
| References | () https://github.com/fluent/fluentd/commit/f5f2b7cddf8aab3932e6dec9fa367a5f3eb27e10 - Patch | |
| References | () https://github.com/fluent/fluentd/pull/5393 - Issue Tracking, Patch | |
| References | () https://github.com/fluent/fluentd/releases/tag/v1.19.3 - Product, Release Notes | |
| References | () https://github.com/fluent/fluentd/security/advisories/GHSA-j9cw-hwqf-85w7 - Mitigation, Vendor Advisory |
08 Jul 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 22:17
Updated : 2026-07-13 18:48
NVD link : CVE-2026-44160
Mitre link : CVE-2026-44160
CVE.ORG link : CVE-2026-44160
JSON object : View
Products Affected
fluentd
- fluentd
CWE
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
