Feed/CVE-2026-54680
CVE-2026-54680CRITICALCVSS 9.9

CVE-2026-54680

Published Jul 29, 2026·Updated Jul 29, 2026

NVD Description

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd <match **> block using @type exec and execute arbitrary commands inside the Fluentd aggregator. This issue is fixed in version 6.6.0.

Affected Packages (1)

github.com/kube-logging/logging-operatorGO
Fixed in 0.0.0-20260608145523-cf437d7f1e05

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free