Description
fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry ingestion endpoint was exposed to an untrusted network, an attacker could send an excessively large request or a highly compressed payload that expanded in memory. The resulting memory exhaustion could cause the operating system to terminate the Fluentd process, disrupting all log collection and forwarding on the affected node. This issue is fixed in version 0.5.3.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

fluent‑plugin‑opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to version 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompresses payloads into memory without enforcing maximum size thresholds. When the OpenTelemetry ingestion endpoint is exposed to an untrusted network, an attacker can send an excessively large request or a highly compressed payload that expands in memory, exhausting system memory and causing the Fluentd process to terminate. This disruption halts all log collection and forwarding on the affected node. The issue is fixed by upgrading to version 0.5.3.

Affected Systems

The vulnerability affects the fluent‑plugins‑nursery implementation of fluent‑plugin‑opentelemetry prior to version 0.5.3. Systems running any earlier release expose an OpenTelemetry ingestion endpoint to an untrusted network and are susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. An EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network access to the OpenTelemetry ingestion endpoint, and successful exploitation results in a denial of service that disrupts logging infrastructure, potentially impacting monitoring and alerting capabilities.

Generated by OpenCVE AI on September 20, 2026 at 15:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update fluent‑plugin‑opentelemetry to version 0.5.3 or later, which enforces request size limits on the in_opentelemetry HTTP input.
  • Restrict the OpenTelemetry ingestion endpoint to trusted networks or place it behind a firewall so that only authorized clients can send data.
  • Configure application or infrastructure limits on maximum request body size and monitor Fluentd memory usage to detect anomalous spikes.

Generated by OpenCVE AI on September 20, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2jc5-xhx8-qj6h fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fluent-plugins-nursery
Fluent-plugins-nursery fluent-plugin-opentelemetry
Vendors & Products Fluent-plugins-nursery
Fluent-plugins-nursery fluent-plugin-opentelemetry

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry ingestion endpoint was exposed to an untrusted network, an attacker could send an excessively large request or a highly compressed payload that expanded in memory. The resulting memory exhaustion could cause the operating system to terminate the Fluentd process, disrupting all log collection and forwarding on the affected node. This issue is fixed in version 0.5.3.
Title fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Fluent-plugins-nursery Fluent-plugin-opentelemetry
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:02:06.130Z

Reserved: 2026-05-05T14:39:34.922Z

Link: CVE-2026-44163

cve-icon Vulnrichment

Updated: 2026-09-16T16:02:02.131Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:09.823

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-44163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)