<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T12:15:56.247752+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369678</id>
    <title>EUVD-2026-369678</title>
    <updated>2026-10-08T12:15:56.301451+00:00</updated>
    <content>EUVD-2026-369678</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44163</id>
    <title>fkie_cve-2026-44163</title>
    <updated>2026-10-08T12:15:56.301491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry ingestion endpoint was exposed to an untrusted network, an attacker could send an excessively large request or a highly compressed payload that expanded in memory. The resulting memory exhaustion could cause the operating system to terminate the Fluentd process, disrupting all log collection and forwarding on the affected node. This issue is fixed in version 0.5.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2jc5-xhx8-qj6h</id>
    <title>GHSA-2jc5-xhx8-qj6h — fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`</title>
    <updated>2026-10-08T12:15:56.301529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: fluent-plugin-opentelemetry</p>
<p>The `fluent-plugin-opentelemetry` plugin (specifically the `in_opentelemetry` HTTP input) lacked strict size limits on incoming requests.
It was discovered that the plugin read the entire request body and decompressed payloads into memory without enforcing maximum size thresholds.</p>
<p>If the OpenTelemetry ingestion endpoint is exposed to untrusted networks, an attacker can send an excessively large HTTP request or a maliciously crafted, highly compressed payload.
When the plugin attempts to read or decompress this payload, it will expand to an excessive size and it will consume significant system resources.</p>
<p>### Impact
This vulnerability allows for a **Denial of Service (DoS)** attack via memory exhaustion. 
The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system.
This results in the disruption of all log collection and forwarding capabilities on the affected node.</p>
<p>### Patches
v0.5.3</p>
<p>### Workarounds
If an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:</p>
<p>1. Restrict Network Access
   * Ensure that the OpenTelemetry ingestion ports (default `4318`) are deployed within a closed, trusted network. Use firewall rules (e.g., iptables, AWS Security Groups) to block access from untrusted networks or instances.
2. Use a Reverse Proxy
   * If you must expose HTTP ingestion to external sources, place a robust reverse proxy (such as Nginx) in front of Fluentd…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2jc5-xhx8-qj6h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-000090</id>
    <title>jvndb-2026-000090</title>
    <updated>2026-10-08T12:15:56.301614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fluentd provided by Fluentd Project contains multiple vulnerabilities listed below.  &lt;a href='https://cwe.mitre.org/data/definitions/22.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://www.cve.org/CVERecord?id=CVE-2026-44024' target='_blank'&gt;&lt;/a&gt;&lt;a href='https://cwe.mitre.org/data/definitions/306.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='http://www.cve.org/CVERecord?id=CVE-2026-44025' target='_blank'&gt;&lt;/a&gt;    &lt;a href='https://cwe.mitre.org/data/definitions/409.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='http://www.cve.org/CVERecord?id=CVE-2026-44160' target='_blank'&gt;&lt;/a&gt;  &lt;a href='https://cwe.mitre.org/data/definitions/918.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='http://www.cve.org/CVERecord?id=CVE-2026-44161' target='_blank'&gt;&lt;/a&gt;  &lt;a href='https://cwe.mitre.org/data/definitions/409.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='http://www.cve.org/CVERecord?id=CVE-2026-44162' target='_blank'&gt;&lt;/a&gt;  &lt;a href='https://cwe.mitre.org/data/definitions/409.html' target='_blank'&gt;&lt;/a&gt;&lt;a href='http://www.cve.org/CVERecord?id=CVE-2026-44163' target='_blank'&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;Path traversal in ${tag} Placeholder (CWE-22) - CVE-2026-44024&lt;/li&gt;&lt;li&gt;Missing authentication for critical function in Monitor Agent API (CWE-306) - CVE-2026-44025&lt;/li&gt;&lt;li&gt;Improper handling of highly compressed data in in_http and in_forward  (CWE-409) - CVE-2026-44160&lt;/li&gt;&lt;li&gt;Server-side request forgery in out_http (CWE-918) - CVE-2026-44161&lt;/li&gt;&lt;li&gt;Improper handling of highly compressed data in in_s3 (CWE-409) - CVE-2026-44162&lt;/li&gt;&lt;li&gt;Improper handling of high…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-000090"/>
  </entry>
</feed>
