CVE-2026-44024
CRITICALFluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Title source: cnaDescription
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing path traversal characters to write or overwrite arbitrary files and potentially achieve remote code execution. This issue is fixed in version 1.19.3.
References (4)
Core 4
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/fluent/fluentd/pull/5391
X_Refsource_Confirm x_refsource_confirm
https://github.com/fluent/fluentd/security/advisories/GHSA-44hj-4m45-frj3
X_Refsource_Misc x_refsource_misc
https://github.com/fluent/fluentd/commit/45c87a81f3ac0b72b3f9dcfe8cfb5f9038f81437
X_Refsource_Misc x_refsource_misc
https://github.com/fluent/fluentd/releases/tag/v1.19.3
Scores
CVSS v3
9.8
EPSS
0.0109
EPSS Percentile
62.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (2)
fluent/fluentd
< 1.19.3
fluentd/fluentd
< 1.19.3
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026