CVE-2026-44025
HighAdvisory
Published 26 Jun 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 40th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 16
- of 17,781 indexed, latest versions
- Container images
- 13
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 13 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| fluentdgem | 0.12.43, 1.2.6, 1.3.3, 1.4.2+8 more | 1.19.3 | 13 |
- OSV records
- GHSA-pr7j-96cj-549h
- Also known as
- BIT-fluentd-2026-44025
Charts affected
16 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| efkcryptexlabsVerified publisher | 7.17.3 | 1 of 3See more | 1,299 |
| fluentdbryanalves | 0.1.0 | 1 of 1See more | 723 |
| fluentd-cloudwatchcloudnativeapp | 0.9.0 | 1 of 2See more | 1,342 |
| fluentd-kubernetes-awscloudposse | 0.2.1 | 1 of 2See more | 1,305 |
| monitoring-stackdata354-helmVerified publisher | 1.4.2 | 1 of 4See more | 3,176 |
| coralogix-fluentddevtron | 1.0.3 | 1 of 1See more | 750 |
| coralogix-fluentddevtron-labs | 1.0.3 | 1 of 1See more | 750 |
| gwangju_2-3gwangju2-3 | 0.1.0 | 1 of 5See more | 6,491 |
| fluentdhelm | 0.2.16 | 1 of 1See more | 1,217 |
| coralogix-fluentdhelmtest | 1.0.4 | 1 of 1See more | 750 |
| fluentd-elasticsearchkfirfer | 13.9.1 | 1 of 1See more | 1,178 |
| lm-logslogicmonitorVerified publisher | 0.3.5 | 1 of 1See more | 1,029 |
| fluentd-papertrailmozilla | 0.2.2 | 1 of 1See more | 1,001 |
| coralogix-fluentdromholdings | 1.0.3 | 1 of 1See more | 750 |
| fluentdslamdev | 0.0.6 | 1 of 1See more | 1,384 |
| fluentd-operatorstatcan | 0.5.1 | 1 of 1See more | 1,955 |
Container images carrying it
13 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.