Description
fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_limit. An attacker with permission to upload objects to the monitored S3 bucket can provide a highly compressed object that expands excessively when Fluentd processes it. The resulting memory exhaustion can cause the operating system to terminate the Fluentd process and disrupt all log collection on the affected node. This issue is fixed in version 1.8.5.
Published: 2026-09-14
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The fluent-plugin-s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a limit. An attacker who can upload objects to the monitored S3 bucket can provide a highly compressed file that expands explosively when Fluentd processes it, causing memory exhaustion. The operating system may then terminate the Fluentd process, disrupting all log collection on the affected node. This resource exhaustion flaw is identified as CWE-409.

Affected Systems

The vulnerability affects fluent-plugin-s3, a plugin used by Fluentd to read from and write to Amazon S3. All releases from 0.7.0 through 1.8.4 are impacted; the fix is included in version 1.8.5 and later.

Risk and Exploitability

The CVSS score is 2.7, indicating low overall severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is below 1%, suggesting a very low probability of exploitation. Exacerbation requires the attacker to have write permission to the monitored S3 bucket, so the attack surface is limited to users with such access. A single crafted object can trigger the attack, and if no mitigation is in place, the affected node will experience a service interruption until the Fluentd process is restarted.

Generated by OpenCVE AI on September 20, 2026 at 23:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade fluent-plugin-s3 to version 1.8.5 or newer to apply the vendor fix.
  • Restrict write permissions on the monitored S3 bucket to trusted users or a minimal set of accounts, and consider separate buckets for untrusted traffic.
  • Monitor Fluentd memory usage and set alerts for sudden spikes; configure process monitoring to automatically restart Fluentd if the process terminates unexpectedly.

Generated by OpenCVE AI on September 20, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xv9w-7v6q-hpjh fluent-plugin-s3 Vulnerable to Denial of Service (DoS) via Decompression Bomb in `in_s3`
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fluent
Fluent fluent-plugin-s3
Vendors & Products Fluent
Fluent fluent-plugin-s3

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_limit. An attacker with permission to upload objects to the monitored S3 bucket can provide a highly compressed object that expands excessively when Fluentd processes it. The resulting memory exhaustion can cause the operating system to terminate the Fluentd process and disrupt all log collection on the affected node. This issue is fixed in version 1.8.5.
Title fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Fluent Fluent-plugin-s3
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:14:18.270Z

Reserved: 2026-05-05T14:39:34.922Z

Link: CVE-2026-44162

cve-icon Vulnrichment

Updated: 2026-09-14T18:14:11.383Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:47.513

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-44162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)