THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mjqf-28ph-426h (critical) — Logging operator has Fluentd configuration injection that allows remote code execution

[GHSA] GHSA-mjqf-28ph-426h (critical) — Logging operator has Fluentd configuration injection that allows remote code execution

highgithub_advisoriesPublished 2026-07-29

GHSA-mjqf-28ph-426h Severity: critical CVE: CVE-2026-54680

Logging operator has Fluentd configuration injection that allows remote code execution

### Summary

The Fluentd configuration renderer in Logging operator writes strings from CRDs such as `Flow` directly into `fluent.conf` without escaping them. As a result, a user who can create `Flow` resources can inject Fluentd configuration by provi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mjqf-28ph-426h