THREAT OPS › Threat News › [GHSA] GHSA-mjqf-28ph-426h (critical) — Logging operator has Fluentd configuration injection that allows remote code execution
[GHSA] GHSA-mjqf-28ph-426h (critical) — Logging operator has Fluentd configuration injection that allows remote code execution
GHSA-mjqf-28ph-426h Severity: critical CVE: CVE-2026-54680
Logging operator has Fluentd configuration injection that allows remote code execution
### Summary
The Fluentd configuration renderer in Logging operator writes strings from CRDs such as `Flow` directly into `fluent.conf` without escaping them. As a result, a user who can create `Flow` resources can inject Fluentd configuration by provi
Indicators of compromise
- 98275d2984aa8d731c4c975b8006aa433fc7bafasha1
- CVE-2026-54680cve
- http://169.254.169.254/latest/meta-data/instance-idurl
- logging.banzaicloud.iodomain
Original source: https://github.com/advisories/GHSA-mjqf-28ph-426h