Executive brief
Fluentd is a popular data collection tool used to gather logs and events from various sources and send them to storage or analysis platforms. A security flaw in its HTTP output plugin allows attackers to manipulate where these logs are sent by injecting malicious data into event tags. This could allow an attacker to bypass network security controls and force the server to send requests to internal systems, potentially exposing sensitive internal data or cloud metadata.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Fluentd's 'out_http' output plugin due to insufficient validation of dynamic placeholders (e.g., ${tag}) in the endpoint configuration. If a placeholder value is derived from untrusted input, a remote attacker can manipulate the destination hostname of outbound HTTP requests. This allows the attacker to force Fluentd to send POST or PUT requests to arbitrary internal services or cloud metadata endpoints (like AWS IMDS). The vulnerability is addressed in version 1.19.3 by introducing strict host validation and a new 'allowed_hosts' parameter to explicitly define permitted destination hostnames.
Affected products
- Fluent Fluentd < 1.19.3
Timeline
- 2026-06-25: patched: Fix merged into v1.19 branch and version 1.19.3 released.
- 2026-06-26: advisory: GitHub Security Advisory GHSA-72f5-rr8c-r6gr published.
- 2026-07-08: disclosed: CVE-2026-44161 published to NVD.