CVE-2021-41186 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting Fluentd versions 0.14.14 to 1.14.1 when using the parser_apache2 plugin. An attacker can craft a malformed Apache log entry that causes the regular expression to consume excessive processing time, leading to a denial of service. This vulnerability has a CVSS score of 7.5 (High), indicating a critical severity. It can be exploited remotely with low attack complexity and no user interaction, resulting in a complete denial of service for the affected Fluentd instance. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. Patches are available in Fluentd version 1.14.2, and workarounds include avoiding the parser_apache2 plugin for untrusted logs or manually applying the patched plugin file.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.14.14, <= 1.14.1CPE matchmatch criteria | cpe:2.3:a:fluentd:fluentd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.