Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.4%top 66%

BIT-fluentd-2026-44025: Fluentd: Exposure of Sensitive Information via Monitor Agent API

0
High
Published: 07/14/2026 (07/14/2026, 08:42:50 UTC)
Source: GCVE Database
Vendor/Project: fluent
Product: fluentd

Description

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins.json and related endpoints unintentionally include internal instance variables that may contain database passwords, API keys, or cloud credentials. This issue is fixed in version 1.19.3.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected software

RubyGemsghsa
fluentd
Affected versions
<1.19.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/09/2026, 08:10:57 UTC

Technical Analysis

The Monitor Agent plugin in Fluentd versions before 1.19.3 exposes internal plugin instance variables via its REST API, potentially leaking sensitive data including database credentials and API keys. An attacker with network access to the Monitor Agent port (default 24220) can exploit this vulnerability to retrieve such sensitive information. This vulnerability is identified as CVE-2026-44025 and is classified under CWE-200 (Exposure of Sensitive Information) and CWE-306 (Missing Authentication for Critical Function). The vulnerability has a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating high confidentiality impact with no required privileges or user interaction. A fixed version, 1.19.3, is available to remediate this issue.

Potential Impact

An attacker who can connect to the Monitor Agent port can obtain sensitive internal plugin data, including secrets like database passwords and API keys. This exposure can lead to unauthorized access to backend systems or data breaches. The impact is high confidentiality loss but does not affect integrity or availability. The risk is contingent on network exposure of the Monitor Agent port and the specific plugin configurations in use.

Mitigation Recommendations

A patch is available in Fluentd version 1.19.3 that fixes this vulnerability. Users should upgrade to version 1.19.3 or later to remediate the issue. Until upgrading, it is recommended to restrict access to the Monitor Agent port (default 24220) to localhost only or block the port using firewall rules to prevent unauthorized network access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-pr7j-96cj-549h
Osv Schema Version
1.4.0
Aliases
["CVE-2026-44025"]
Ecosystems
["RubyGems"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a3ef79627e9c79719ff8e84

Added to database: 06/26/2026, 22:05:10 UTC

Last enriched: 07/09/2026, 08:10:57 UTC

Last updated: 08/09/2026, 00:41:14 UTC

Views: 76

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses