lowCVSS 2.7Vulnerability

CVE-2026-44162

The `fluent-plugin-s3` plugin (specifically the `in_s3` input plugin) supports reading and decompressing heavily compressed files (such as `gzip`, `lzma2`, and `lzop`) from Amazon S3. It was discovered that the plugin read the entire decompressed payload into memory at once without enforcing a strict size limit. If an attacker has sufficient permissions to upload files to the monitored S3 bucket, they can upload a maliciously crafted, highly compressed file. When Fluentd attempts to decompress this file, it will expand to an excessive size and it will consume significant system resources. ### Impact This vulnerability allows for a **Denial of Service (DoS)** attack via memory exhaustion. The rapid memory consumption during decompression can lead to an Out-of-Memory kill of the Fluentd process by the operating system, This results in the disruption of all log collection on the affected node. ### Patches v1.8.5 ### Workarounds If an immediate upgrade is not possible, mitigate the risk by applying strict IAM access controls: 1. Restrict Bucket Access * Ensure that write (PUT) access to the S3 bucket monitored by `in_s3` is strictly limited to trusted services and administrators. Prevent any public or untrusted uploads to the S3 bucket.

Properties

ghsa_id
GHSA-xv9w-7v6q-hpjh
severity
low
summary
fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`
cvss_score
2.7
cve_id
CVE-2026-44162
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
is_ghsa_only
false
ghsa_published
2026-06-26T17:02:19Z
source_url
https://github.com/advisories/GHSA-xv9w-7v6q-hpjh
ghsa_updated
2026-06-26T17:02:21Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rubygems/fluent-plugin-s3

AFFECTS (1)

[Software]rubygems/fluent-plugin-s3

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-44162 (CVSS 2.7) — Ninja Signal Threat Intelligence | Ninja Signal