CVE-2026-44162Low· 2.7▾ Sunlitfluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_l…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_limit. An attacker with permission to upload objects to the monitored S3 bucket can provide a highly compressed object that expands excessively when Fluentd processes it. The resulting memory exhaustion can cause the operating system to terminate the Fluentd process and disrupt all log collection on the affected node. This issue is fixed in version 1.8.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
fluent-plugin-s3 >= 0.7.0, <= 1.8.4Patched in:
fluent-plugin-s3 1.8.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44163Medium· 5.3fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data
CVE-2026-77528Medium· 5.3Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio
CVE-2026-92000High· 7.5adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size
CVE-2026-1526High· 7.5The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression
CVE-2026-40192High· 7.5Pillow is a Python imaging library
CVE-2025-61726High· 7.5The net/url package does not set a limit on the number of query parameters in a query