Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
Published: June 26, 2026
SECURITY IDENTIFIERS
- CVE: CVE-2026-44161 (NVD)
- GHSA: GHSA-72f5-rr8c-r6gr
GEM
SEVERITY
CVSS v3.x: 7.2 (High)
PATCHED VERSIONS
>= 1.19.3
DESCRIPTION
The out_http output plugin allows the use of placeholders (such as
${tag}) in the endpoint configuration parameter. It was discovered
that if the placeholder value is derived from untrusted user input,
an attacker can maliciously control the destination hostname of the
outbound HTTP requests made by Fluentd.
Impact
This vulnerability allows for a Server-Side Request Forgery (SSRF)
attack. An unauthenticated attacker can force the Fluentd node to send
HTTP requests to arbitrary internal services. This can lead to
unauthorized access to internal APIs, data exfiltration, or the
compromise of cloud metadata endpoints (e.g., AWS IMDS 169.254.169.254).
