BIT-fluentd-2026-44024

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/fluentd/BIT-fluentd-2026-44024.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-fluentd-2026-44024
Aliases
Published
2026-07-14T08:42:49Z
Modified
2026-09-08T08:47:31Z
Summary
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Details

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing path traversal characters to write or overwrite arbitrary files and potentially achieve remote code execution. This issue is fixed in version 1.19.3.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:fluentd:fluentd:*:*:*:*:*:ruby:*:*"
    ],
    "severity":  "Critical"
}
References

Affected packages

Bitnami / fluentd

Package

Name
fluentd
Purl
pkg:bitnami/fluentd

Severity

  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/fluentd/BIT-fluentd-2026-44024.json"