Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5601 articles · 220742 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-44163PATCHED
rubygems · fluent-plugin-opentelemetry

fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`

Description

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry ingestion endpoint was exposed to an untrusted network, an attacker could send an excessively large request or a highly compressed payload that expanded in memory. The resulting memory exhaustion could cause the operating system to terminate the Fluentd process, disrupting all log collection and forwarding on the affected node. This issue is fixed in version 0.5.3.

Affected Products

VendorProductVersions
rubygemsfluent-plugin-opentelemetry< 0.5.3

References

  • https://github.com/fluent-plugins-nursery/fluent-plugin-opentelemetry/security/advisories/GHSA-2jc5-xhx8-qj6h(x_refsource_CONFIRM)
  • https://github.com/fluent-plugins-nursery/fluent-plugin-opentelemetry/commit/ce6c1f2a7741592c8a79afbe75fded9e8ebfa92d(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB6d ago
CVE-2026-44163 | fluent-plugins-nursery fluent-plugin-opentelemetry up to 0.5.2 memory allocation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
fluent-plugin-opentelemetry@0.5.3
CWECWE-409
PublishedJun 26, 2026
Tags
GHSA-2jc5-xhx8-qj6hrubygems
Trending Score15
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-66066EXPKEV
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 13
HIGHCVE-2026-50276
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Trending: 13
MEDIUMCVE-2026-54171
Excon: redact additional sensitive/risky headers when following redirects
Trending: 10
LOWCVE-2026-44162
fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`
Trending: 6
MEDIUMCVE-2026-53769
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Patch Available
Sep 16, 2026