<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:59:22 +0000</lastBuildDate>
    <item>
      <title>BIT-fluentd-2026-44160 — Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`</title>
      <link>https://cve.radiocsirt.org/vuln/bit-fluentd-2026-44160</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: fluentd&lt;/p&gt;
&lt;p&gt;Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd&amp;#39;s in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: fluentd&lt;/p&gt;
&lt;p&gt;Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd&amp;#39;s in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-fluentd-2026-44160</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-PM11258 — Security fix for CVE-2026-44160 applied in: kube-logging-operator 6.7.0-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-pm11258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kube-logging-operator&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the kube-logging-operator package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kube-logging-operator&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the kube-logging-operator package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-pm11258</guid>
    </item>
    <item>
      <title>EUVD-2026-335489</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335489</link>
      <description>EUVD-2026-335489</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335489</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44160</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44160</link>
      <description>&lt;p&gt;Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd&amp;#39;s in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd&amp;#39;s in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44160</guid>
    </item>
    <item>
      <title>GHSA-j9cw-hwqf-85w7 — Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j9cw-hwqf-85w7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: fluentd&lt;/p&gt;
&lt;p&gt;Fluentd&amp;#39;s `in_http` and `in_forward` plugins support receiving gzip-compressed data.
While Fluentd correctly enforces size limits on the incoming compressed payloads (e.g., via `body_size_limit` or `chunk_size_limit`), it was discovered that there is no limit enforced on the size of the decompressed data.&lt;/p&gt;
&lt;p&gt;If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. 
When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability allows for a **Denial of Service (DoS)** attack via memory exhaustion. 
The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system.
This results in the disruption of all log collection and forwarding capabilities on the affected node.&lt;/p&gt;
&lt;p&gt;### Patches
v1.19.3&lt;/p&gt;
&lt;p&gt;### Workarounds
If an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:&lt;/p&gt;
&lt;p&gt;1. Restrict Network Access
   * Ensure that Fluentd input ports (such as `9880` for `in_http` and `24224` for `in_forward`) are deployed within a closed, trusted network. Use firewall rules (e.g., iptables, AWS Security Groups) to block access from untrusted networks or instances.
2. Use a Reverse Proxy
   * If developers must expose HTTP ingestion to external sources, place a robust reverse proxy (such as Nginx) in fro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: fluentd&lt;/p&gt;
&lt;p&gt;Fluentd&amp;#39;s `in_http` and `in_forward` plugins support receiving gzip-compressed data.
While Fluentd correctly enforces size limits on the incoming compressed payloads (e.g., via `body_size_limit` or `chunk_size_limit`), it was discovered that there is no limit enforced on the size of the decompressed data.&lt;/p&gt;
&lt;p&gt;If a Fluentd instance is exposed to untrusted networks, an attacker can send a maliciously crafted, highly compressed payload. 
When Fluentd attempts to decompress this payload in memory, it will expand to an excessive size, completely bypassing the intended payload size limits.&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability allows for a **Denial of Service (DoS)** attack via memory exhaustion. 
The rapid memory consumption during decompression can easily lead to an Out-of-Memory kill of the Fluentd process by the operating system.
This results in the disruption of all log collection and forwarding capabilities on the affected node.&lt;/p&gt;
&lt;p&gt;### Patches
v1.19.3&lt;/p&gt;
&lt;p&gt;### Workarounds
If an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:&lt;/p&gt;
&lt;p&gt;1. Restrict Network Access
   * Ensure that Fluentd input ports (such as `9880` for `in_http` and `24224` for `in_forward`) are deployed within a closed, trusted network. Use firewall rules (e.g., iptables, AWS Security Groups) to block access from untrusted networks or instances.
2. Use a Reverse Proxy
   * If developers must expose HTTP ingestion to external sources, place a robust reverse proxy (such as Nginx) in fro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j9cw-hwqf-85w7</guid>
    </item>
    <item>
      <title>jvndb-2026-000090</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-000090</link>
      <description>&lt;p&gt;Fluentd provided by Fluentd Project contains multiple vulnerabilities listed below.  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/22.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://www.cve.org/CVERecord?id=CVE-2026-44024&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/306.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44025&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;    &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/409.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44160&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/918.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44161&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/409.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44162&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/409.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44163&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Path traversal in ${tag} Placeholder (CWE-22) - CVE-2026-44024&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing authentication for critical function in Monitor Agent API (CWE-306) - CVE-2026-44025&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper handling of highly compressed data in in_http and in_forward  (CWE-409) - CVE-2026-44160&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Server-side request forgery in out_http (CWE-918) - CVE-2026-44161&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper handling of highly compressed data in in_s3 (CWE-409) - CVE-2026-44162&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper handling of high…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fluentd provided by Fluentd Project contains multiple vulnerabilities listed below.  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/22.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://www.cve.org/CVERecord?id=CVE-2026-44024&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/306.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44025&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;    &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/409.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44160&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/918.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44161&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/409.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44162&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;  &amp;lt;a href=&amp;#39;https://cwe.mitre.org/data/definitions/409.html&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;a href=&amp;#39;http://www.cve.org/CVERecord?id=CVE-2026-44163&amp;#39; target=&amp;#39;_blank&amp;#39;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;ul&amp;gt;&amp;lt;li&amp;gt;Path traversal in ${tag} Placeholder (CWE-22) - CVE-2026-44024&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Missing authentication for critical function in Monitor Agent API (CWE-306) - CVE-2026-44025&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper handling of highly compressed data in in_http and in_forward  (CWE-409) - CVE-2026-44160&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Server-side request forgery in out_http (CWE-918) - CVE-2026-44161&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper handling of highly compressed data in in_s3 (CWE-409) - CVE-2026-44162&amp;lt;/li&amp;gt;&amp;lt;li&amp;gt;Improper handling of high…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-000090</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2096 — Fluentd: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2096</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Fluentd ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Fluentd ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2096</guid>
    </item>
  </channel>
</rss>
