{"id":"CVE-2026-44160","aliases":["BIT-fluentd-2026-44160","GHSA-j9cw-hwqf-85w7"],"url":"https://o3.security/vulnerability/CVE-2026-44160","summary":"Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`","details":"Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as body_size_limit and chunk_size_limit, allowing crafted compressed payloads to decompress in memory to an excessive size and cause denial of service through memory exhaustion. This issue is fixed in version 1.19.3.","published":"2026-07-08T21:24:28.346Z","modified":"2026-08-12T03:51:47.442981362Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.0036,"percentile":0.29335,"asOf":"2026-08-21"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"fluentd","fixedVersion":"1.19.3"}],"fix":{"url":"https://github.com/fluent/fluentd/commit/f5f2b7cddf8aab3932e6dec9fa367a5f3eb27e10","label":"fluent/fluentd@f5f2b7c"},"references":[{"type":"WEB","url":"https://github.com/fluent/fluentd/releases/tag/v1.19.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44160.json"},{"type":"ADVISORY","url":"https://github.com/fluent/fluentd/security/advisories/GHSA-j9cw-hwqf-85w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44160"},{"type":"FIX","url":"https://github.com/fluent/fluentd/commit/f5f2b7cddf8aab3932e6dec9fa367a5f3eb27e10"},{"type":"FIX","url":"https://github.com/fluent/fluentd/pull/5393"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.442981362Z"}}