fluentd vulnerabilities
CVEs whose affected-version data names the fluentd package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-44024Critical· 9.8PoCFluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-44025High· 7.5Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
▾ Twilightfluentd · fluentdEPSS 0.47%via GHSA
CVE-2026-44160High· 7.5Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
▾ Twilightfluentd · fluentdEPSS 0.62%via GHSA
CVE-2026-44161High· 7.2Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
▾ Twilightfluentd · fluentdEPSS 0.44%via GHSA