Fluentd Configuration Injection in Logging Operator Under Investigation
An early warning has been issued regarding a potential vulnerability in the Fluentd configuration renderer within the Logging operator, which may allow remote code execution due to improper string escaping.
What happened
Reportedly, the Fluentd configuration renderer in the Logging operator writes strings from Custom Resource Definitions (CRDs) directly into the `fluent.conf` file without proper escaping. This appears to create a potential avenue for remote code execution. The vulnerability is under investigation and has been tracked under the ID GHSA-MJQF-28PH-426H.
Affected components include the github.com/kube-logging/logging-operator repository. The issue was reportedly introduced at an unknown version and has been fixed in version 0.0.0-20260608145523-cf437d7f1e05. It is recommended to upgrade to a patched version of the Logging operator once it becomes available and to review Fluentd configurations for any unauthorized changes.
For more detailed information, primary sources should be consulted. The primary source indicates that this vulnerability has been assigned CVE-2026-54680. However, the exact version ranges and dates are currently under investigation and should be verified from the primary sources.
How 0Day mitigates this
github.com/kube-logging/logging-operator is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.