cve-2026-44025
HIGH CVSS 7.5 cvelistv5
Description
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3.
Timeline
- Published
- 2026-07-08 21:23 UTC
- Last Modified
- 2026-07-09
CVSS Details
- Attack Vector
- NETWORK
- Attack Complexity
- LOW
- Privileges Required
- NONE
Affected Products
- fluent fluentd
Weaknesses (CWE)
SSVC (CISA Stakeholder-Specific Vulnerability Categorization)
CISA Coordinator
v2.0.3
- Exploitation
none- Automatable
yes- Technical Impact
partial- Decision timestamp
2026-07-09T13:47:05.851155Z
What is SSVC? — CISA's vulnerability-prioritisation framework using a decision tree rather than a single score.
References
- https://github.com/fluent/fluentd/security/advisories/GHSA-pr7j-96cj-549h x_refsource_CONFIRM
- https://github.com/fluent/fluentd/pull/5392 x_refsource_MISC
- https://github.com/fluent/fluentd/commit/990921518971699b9a97441970674d1800e29177 x_refsource_MISC
- https://github.com/fluent/fluentd/releases/tag/v1.19.3 x_refsource_MISC
Linked Vulnerabilities
No linked vulnerabilities found.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-44025",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-09T13:47:05.851155Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-09T13:47:17.414Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "fluentd",
"vendor": "fluent",
"versions": [
{
"status": "affected",
"version": "< 1.19.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "CWE-306: Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-08T21:23:16.920Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/fluent/fluentd/security/advisories/GHSA-pr7j-96cj-549h",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/fluent/fluentd/security/advisories/GHSA-pr7j-96cj-549h"
},
{
"name": "https://github.com/fluent/fluentd/pull/5392",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/fluent/fluentd/pull/5392"
},
{
"name": "https://github.com/fluent/fluentd/commit/990921518971699b9a97441970674d1800e29177",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/fluent/fluentd/commit/990921518971699b9a97441970674d1800e29177"
},
{
"name": "https://github.com/fluent/fluentd/releases/tag/v1.19.3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/fluent/fluentd/releases/tag/v1.19.3"
}
],
"source": {
"advisory": "GHSA-pr7j-96cj-549h",
"discovery": "UNKNOWN"
},
"title": "Fluentd: Exposure of Sensitive Information via Monitor Agent API"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-44025",
"datePublished": "2026-07-08T21:23:16.920Z",
"dateReserved": "2026-05-04T21:24:36.506Z",
"dateUpdated": "2026-07-09T13:47:17.414Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Enrichment data
Aggregated bundle (all enrichments)