Fluentd V1.19.3 Has Been Released
Additionally, similar vulnerability was also fixed in the following fluentd plugins:
In most cases, there is no problem using deployed Fluentd within a closed, trusted network. If you could not update Fluentd immediately, consider to take advised mitigation in above advisories.
Many bugs were also fixed in this release.
Historically, in_debug_agent accepts remote access by default.
This behavior is not problem because usually in_debug_agent must be explicitly enabled by users who know what you do.
But, there is an security concern which accepts external access by default even though user must enable it explicitly.
To mitigate security concern, changed that behavior a bit secure by default.
If you dare to keep non-secure behavior, specify 0.0.0.0 explicitly.
If buffer path contains [] in tag something like "path test/${tag[0]}", when resuming buffer process can't find them without escaping bracket.
Thus buffer files remains under that directory.
In this release, that can be resumed correctly.
Note that recommended tag spec is specified in routing documentation, but it is easily shoot your legs in practical use-case if you use [] characters. so it is changed to take care of that case.
In the versions, there was a keepalive socket reuse bug.
When a cached keepalive connection has already been closed by the remote side, out_forward could pick that socket back up and try to write to it again.
As a result, that left the flush thread spinning on a dead socket and can drive CPU usage to 100%.
If data containing non-latin characters are stored onto disk using the storage_local plugin, the file is properly written but cannot be read again once fluentd restarts. Now that behaviour was fixed by properly handling the file encoding.
In this release, added some warnings for problematic use-cases.
If there are any potential issues with your configuration, Fluentd detects above cases additionally.
We have been posting information Fluentd in Japanese on @fluentd_jp . We would appreciate it if you followed the X account.
ClearCode, Inc. is a software company specializing in the development of Free Software. We maintain Fluentd and its plugin ecosystem, and provide commercial support for them.
Fluentd is an open source data collector to unify log management.
2025-12-25: Drop schedule announcement EOL of Fluent Package (fluent-package) 5
2025-09-04: Upgrade Guide for fluent-package v6
2024-08-29: Scheduled support lifecycle announcement Fluent Package v6
2023-08-29: Drop schedule announcement EOL of Treasure Agent (td-agent) 4
2023-08-29: Scheduled support lifecycle announcement Fluent Package
2023-07-31: Upgrade to fluent-package v5
2026-06-26: fluent-package v6.0.4 has been released
2026-06-25: Fluentd v1.19.3 has been released
2026-03-27: fluent-package v6.0.3 has been released
2026-02-27: fluent-package v6.0.2 has been released
2026-02-13: Fluentd v1.19.2 has been released
2025-12-25: Drop schedule announcement EOL of Fluent Package (fluent-package) 5
2025-12-19: fluent-package v5.0.9 has been released
2025-12-09: Fluentd v1.16.11 has been released
2025-11-11: fluent-package v6.0.1 has been released
2025-11-06: Fluentd v1.19.1 has been released
Want to learn the basics of Fluentd? Check out these pages.
Couldn't find enough information? Let's ask the community!
You need commercial-grade support from Fluentd committers and experts?
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
