Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5601 articles · 220742 vulns · 37/41 feeds (7d)
← Back to list
2.7
CVE-2026-44162PATCHED
rubygems · fluent-plugin-s3

fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`

Description

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_limit. An attacker with permission to upload objects to the monitored S3 bucket can provide a highly compressed object that expands excessively when Fluentd processes it. The resulting memory exhaustion can cause the operating system to terminate the Fluentd process and disrupt all log collection on the affected node. This issue is fixed in version 1.8.5.

Affected Products

VendorProductVersions
rubygemsfluent-plugin-s3>= 0.7.0, < 1.8.5

References

  • https://github.com/fluent/fluent-plugin-s3/security/advisories/GHSA-xv9w-7v6q-hpjh(x_refsource_CONFIRM)
  • https://github.com/fluent/fluent-plugin-s3/commit/e085aee001d15bcc4bd073507e74075e30550fd0(x_refsource_MISC)
  • https://github.com/fluent/fluent-plugin-s3/releases/tag/v1.8.5(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB7d ago
CVE-2026-44162 | fluent fluent-plugin-s3 up to 1.8.4 In S3 Input Plugin memory allocation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.12.7 LOW
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
fluent-plugin-s3@1.8.5
CWECWE-409
PublishedJun 26, 2026
Tags
GHSA-xv9w-7v6q-hpjhrubygems
Trending Score6
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-44163
fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
Trending: 15
NONECVE-2026-66066EXPKEV
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 13
HIGHCVE-2026-50276
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Trending: 13
MEDIUMCVE-2026-54171
Excon: redact additional sensitive/risky headers when following redirects
Trending: 10
MEDIUMCVE-2026-53769
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Patch Available
Sep 14, 2026