SCA: security update for fluent-plugin-opentelemetry (GHSA-2jc5-xhx8-qj6h)

medium Tenable Cloud Security Plugin ID 444007

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol
data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and
decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry
ingestion endpoint was exposed to an untrusted network, an attacker could send an excessively large
request or a highly compressed payload that expanded in memory. The resulting memory exhaustion could
cause the operating system to terminate the Fluentd process, disrupting all log collection and forwarding
on the affected node. This issue is fixed in version 0.5.3. (CVE-2026-44163)

Solution

Update the fluent-plugin-opentelemetry library and its related packages to version 0.5.3 or later.

See Also

https://github.com/advisories/GHSA-2jc5-xhx8-qj6h

Plugin Details

Severity: Medium

ID: 444007

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 6/26/2026

Updated: 9/16/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-44163

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/26/2026

Vulnerability Publication Date: 6/26/2026

Reference Information

CVE: CVE-2026-44163

cwe: CWE-770