Memory Exhaustion Issue in Fluentd OpenTelemetry Plugin by Fluent Inc.
CVE-2026-44163
5.3MEDIUM
What is CVE-2026-44163?
The Fluentd OpenTelemetry plugin contains a memory exhaustion vulnerability that occurs when the HTTP input handler reads entire incoming request bodies and decompresses payloads without applying maximum size limits. If this plugin is deployed in an environment exposed to untrusted networks, an attacker may exploit this flaw by sending excessively large requests or highly compressed payloads that expand in memory. This could lead to severe memory exhaustion, potentially causing the operating system to terminate the Fluentd process. As a result, all log collection and forwarding operations may be interrupted. The issue is addressed in version 0.5.3 of the plugin.
Affected Version(s)
fluent-plugin-opentelemetry < 0.5.3
