CVE-2026-44161Patch(fluentd / fluentd)

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fluentd fluentd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd out_http output plugin allows placeholders such as ${tag} in the endpoint configuration parameter, and if a placeholder value is derived from untrusted input an attacker can control the destination hostname of outbound HTTP requests and force requests to arbitrary internal services. This issue is fixed in version 1.19.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fluentd

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
fluentd

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 2Technical Details · 2026-07-01: 207-01
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now. #Fluentd #RCE #SSRF #CVE #Cybersecurity #Infosec https://securityonline.info/fluentd-vulnerabilities-v1-19-3 https://t.co/IZ9oEEP23H

    Post summary

    The post announces that a new Fluentd release includes patches for CVE-2026-44024 (9.8 RCE) and CVE-2026-44161 (SSRF) and directs readers to the update.

    00110541
    12.9K followersView on X
  • ChrisUK2026@chris_uk2026
    Patch

    Four Fluentd vulnerabilities are fixed in v1.19.3, including a 9.8 RCE (CVE-2026-44024) and SSRF (CVE-2026-44161). Patch now. @the_yellow_fall #Fluentd #RCE #SSRF #CVE #Cybersecurity #Infosec http://securityonline.info/fluentd-vulner…

    Post summary

    The post announces the release of v1.19.3 for Fluentd, which addresses four vulnerabilities—including a high-severity RCE (CVE-2026-44024) and an SSRF (CVE-2026-44161)—and encourages users to apply the patch.

    0000065
    25 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfluentdfluentd---

Explore more