CRITICAL: github.com/kube-logging/logging-operator — Logging operator has Fluentd configuration injection that allows remote code execution
Summary The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values…
Source github.com/kube-logging/logging-operatorPublished 5d ago · Jul 29, 2026Posted on Threads

What we hold
- Package
- github.com/kube-logging/logging-operator
- Ecosystem
- go
- Severity
- CRITICAL
- ID
- CVE-2026-54680
Summary The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values…