fluentd records
8 published records for vendor fluentd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-306 Missing Authentication for Critical Function1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2022-39379No exploit | Fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)fluentd · fluentd · CWE-502 | Critical9.8 | — | 45.0% | Nov 2, 2022 |
40Plan | CVE-2017-10906No exploit | Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execufluentd · fluentd | Critical9.8 | — | 4.6% | Dec 8, 2017 |
39Monitor | CVE-2026-44024Proof of concept | Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholderfluentd · fluentd · CWE-22 | Critical9.8 | — | 1.1% | Jul 8, 2026 |
35Monitor | CVE-2020-21514No exploit | An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default passwfluentd · fluentd · CWE-276 | High8.8 | — | 0.8% | Apr 4, 2023 |
31Monitor | CVE-2021-41186No exploit | ReDoS vulnerability in parser_apache2fluentd · fluentd · CWE-400 | High7.5 | — | 2.2% | Oct 29, 2021 |
30Monitor | CVE-2026-44160No exploit | Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`fluentd · fluentd · CWE-409 | High7.5 | — | 0.6% | Jul 8, 2026 |
30Monitor | CVE-2026-44025No exploit | Fluentd: Exposure of Sensitive Information via Monitor Agent APIfluentd · fluentd · CWE-306 | High7.5 | — | 0.5% | Jul 8, 2026 |
28Monitor | CVE-2026-44161No exploit | Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`fluentd · fluentd · CWE-918 | High7.2 | — | 0.4% | Jul 8, 2026 |
- CVE-2022-3937952Plan
Fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
CriticalCVSS 9.8No exploitEPSS 45%fluentd · fluentdNov 2, 2022
- CVE-2017-1090640Plan
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execu
CriticalCVSS 9.8No exploitEPSS 5%fluentd · fluentdDec 8, 2017
- CVE-2026-4402439Monitor
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CriticalCVSS 9.8Proof of conceptEPSS 1%fluentd · fluentdJul 8, 2026
- CVE-2020-2151435Monitor
An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default passw
HighCVSS 8.8No exploitEPSS 1%fluentd · fluentdApr 4, 2023
- CVE-2021-4118631Monitor
ReDoS vulnerability in parser_apache2
HighCVSS 7.5No exploitEPSS 2%fluentd · fluentdOct 29, 2021
- CVE-2026-4416030Monitor
Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
HighCVSS 7.5No exploitEPSS 1%fluentd · fluentdJul 8, 2026
- CVE-2026-4402530Monitor
Fluentd: Exposure of Sensitive Information via Monitor Agent API
HighCVSS 7.5No exploitEPSS 0%fluentd · fluentdJul 8, 2026
- CVE-2026-4416128Monitor
Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
HighCVSS 7.2No exploitEPSS 0%fluentd · fluentdJul 8, 2026