GHSA-mjqf-28ph-426h
CRITICALCVE-2026-54680The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values that contain newlines.
- Affected
- < 0.0.0-20260608145523-cf437d7f1e05, >=0, <0.0.0-20260608145523-cf437d7f1e05
- Fixed in
- 0.0.0-20260608145523-cf437d7f1e05
- Weakness
- CWE-74
- Published
- 2026-07-29
- Source
- github