CVE-2026-44160
CVE-2026-44160 is a high-severity vulnerability in Fluentd with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-409.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (48th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-409
- Affected product: Fluentd
- Published:
- Last modified:
Description
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.
Frequently asked questions
- What is CVE-2026-44160?
- Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.
- How severe is CVE-2026-44160?
- CVE-2026-44160 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2026-44160 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (48th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-44160?
- CVE-2026-44160 affects Fluentd. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-44160?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-44160 published?
- CVE-2026-44160 was published on 2026-07-08 and last updated on 2026-07-13.
References
- https://github.com/fluent/fluentd/commit/f5f2b7cddf8aab3932e6dec9fa367a5f3eb27e10
- https://github.com/fluent/fluentd/pull/5393
- https://github.com/fluent/fluentd/releases/tag/v1.19.3
- https://github.com/fluent/fluentd/security/advisories/GHSA-j9cw-hwqf-85w7
Affected products (1)
- cpe:2.3:a:fluentd:fluentd:*:*:*:*:*:*:*:*
More vulnerabilities in Fluentd
- CVE-2026-44024 — Critical (CVSS 9.8): Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.…
- CVE-2017-10906 — Critical (CVSS 9.8): Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the…
- CVE-2020-21514 — High (CVSS 8.8): An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code…
- CVE-2026-44025 — High (CVSS 7.5): Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.…
- CVE-2026-44161 — High (CVSS 7.2): Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.…
- CVE-2021-41186 — Medium (CVSS 5.9): Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The…
Other CWE-409 vulnerabilities
- CVE-2026-68911 — High (CVSS 8.7): Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote…
- CVE-2026-77620 — High (CVSS 8.7): Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each…
- CVE-2026-62963 — High (CVSS 8.7): Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket…
- CVE-2026-55195 — High (CVSS 8.7): py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and…
- CVE-2026-53430 — High (CVSS 8.7): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc…
- CVE-2026-44697 — High (CVSS 8.6): Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated…