Fluentd is a widely embedded log-aggregation and stream-processing platform whose compact vulnerability footprint concentrates around the core collector daemon and its web-based management interface, with exposure recurrring through deserialization of untrusted data, improper default permissions, and uncontrolled resource consumption. These weakness classes reflect the product's role as a centralized ingestion point for structured log data from distributed systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fluentd over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39379CRITICAL Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default c | Nov 2, 2022 | 9.8 | 57 | NO | NO |
CVE-2026-44024CRITICAL Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing fil | Jul 8, 2026 | 9.8 | 45 | NO | NO |
CVE-2026-44160HIGH Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins su | Jul 8, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-44161HIGH Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd out_http output plugin allows p | Jul 8, 2026 | 7.2 | 34 | NO | NO |
CVE-2026-44025HIGH Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_a | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2017-10906CRITICAL Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via | Dec 8, 2017 | 9.8 | 32 | NO | NO |
CVE-2020-21514HIGH An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password. | Apr 4, 2023 | 8.8 | 26 | NO | NO |
CVE-2021-41186HIGH Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers fr | Oct 29, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fluentd.
Media articles that mention a CVE ID that affects a product developed by Fluentd — matched by CVE ID, not by vendor name.