Memory Exhaustion Vulnerability in Fluent-plugin-s3 by Fluent Inc.
CVE-2026-44162

2.7LOW

Key Information:

Vendor

Fluent

Vendor
CVE Published:
14 September 2026

What is CVE-2026-44162?

The fluent-plugin-s3, a plugin for Fluentd that interfaces with Amazon S3, is vulnerable to a memory exhaustion issue. Specifically, the in_s3 input plugin fails to enforce a decompression size limit when reading highly compressed objects such as gzip, lzma2, and lzop. An attacker capable of uploading objects to a monitored S3 bucket can exploit this vulnerability by providing a maliciously crafted object that expands significantly when decompressed, leading to excessive memory usage. This can result in the termination of the Fluentd process, disrupting log collection on the affected system. The issue has been resolved in version 1.8.5.

Affected Version(s)

fluent-plugin-s3 >= 0.7.0, < 1.8.5

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.