A high-severity CVE (CVSS 7.5) has been disclosed in Fluentd affecting the `in_http` and `in_forward` plugins. Both plugins support gzip-compressed data but fail to enforce size limits on decompressed output. An attacker on an untrusted network can send a crafted gzip decompression bomb that expands to an excessive size in memory, bypassing configured payload size limits and causing an Out-of-Memory kill of the Fluentd process. This disrupts all log collection and forwarding on the affected node. The vulnerability is patched in Fluentd version 1.19.3 and later.
Table of contents
Impact510 Impressions