{"id":"CVE-2026-44025","aliases":["BIT-fluentd-2026-44025","GHSA-pr7j-96cj-549h"],"url":"https://o3.security/vulnerability/CVE-2026-44025","summary":"Fluentd: Exposure of Sensitive Information via Monitor Agent API","details":"Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3.","published":"2026-07-08T21:23:16.920Z","modified":"2026-08-12T03:51:44.579443349Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00414,"percentile":0.34787,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"fluentd","fixedVersion":"1.19.3"}],"fix":{"url":"https://github.com/fluent/fluentd/commit/990921518971699b9a97441970674d1800e29177","label":"fluent/fluentd@9909215"},"references":[{"type":"WEB","url":"https://github.com/fluent/fluentd/releases/tag/v1.19.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44025.json"},{"type":"ADVISORY","url":"https://github.com/fluent/fluentd/security/advisories/GHSA-pr7j-96cj-549h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44025"},{"type":"FIX","url":"https://github.com/fluent/fluentd/commit/990921518971699b9a97441970674d1800e29177"},{"type":"FIX","url":"https://github.com/fluent/fluentd/pull/5392"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.579443349Z"}}