Impact
The fluent-plugin-s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a limit. An attacker who can upload objects to the monitored S3 bucket can provide a highly compressed file that expands explosively when Fluentd processes it, causing memory exhaustion. The operating system may then terminate the Fluentd process, disrupting all log collection on the affected node. This resource exhaustion flaw is identified as CWE-409.
Affected Systems
The vulnerability affects fluent-plugin-s3, a plugin used by Fluentd to read from and write to Amazon S3. All releases from 0.7.0 through 1.8.4 are impacted; the fix is included in version 1.8.5 and later.
Risk and Exploitability
The CVSS score is 2.7, indicating low overall severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is below 1%, suggesting a very low probability of exploitation. Exacerbation requires the attacker to have write permission to the monitored S3 bucket, so the attack surface is limited to users with such access. A single crafted object can trigger the attack, and if no mitigation is in place, the affected node will experience a service interruption until the Fluentd process is restarted.
OpenCVE Enrichment
Github GHSA