ADVISORY

CRITICAL: github.com/kube-logging/logging-operator — Logging operator has Fluentd configuration injection that allows remote code execution

Summary The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values…

Source github.com/kube-logging/logging-operatorPublished 5d ago · Jul 29, 2026Posted on Threads

What we hold

Package
github.com/kube-logging/logging-operator
Ecosystem
go
Severity
CRITICAL
ID
CVE-2026-54680

Summary The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values…