{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"HIGH"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"Fluentd's Monitor Agent plugin (`in_monitor_agent`) exposes internal metrics and plugin information via a REST API. It was discovered that the API response (`/api/plugins.json` and related endpoints) unintentionally includes internal instance variables of loaded plugins. If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API.",
				"category":"general",
				"title":"Synopsis"
			}
		],
		"publisher":null,
		"references":[
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44025"
			},
			{
				"summary":"CVE-2026-44025 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/cve/2026/csaf-openeuler-cve-2026-44025.json"
			},
			{
				"summary":"openEuler-SA-2026-3538",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3538"
			},
			{
				"summary":"CVE-2026-44025",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-44025&packageName=rubygem-fluentd"
			}
		],
		"title":"openEuler cve CVE-2026-44025",
		"tracking":{
			"initial_release_date":"2026-09-02T09:33:53+08:00",
			"revision_history":[
				{
					"date":"2026-09-02T09:33:53+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-09-02T09:33:53+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-09-02T09:33:53+08:00",
			"id":"CVE-2026-44025",
			"version":"1.0.0",
			"status":"interim"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"openEuler-24.03-LTS-SP3",
									"name":"openEuler-24.03-LTS-SP3"
								},
								"name":"openEuler-24.03-LTS-SP3",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"rubygem-fluentd-1.16.2-2.oe2403sp3.noarch.rpm",
									"name":"rubygem-fluentd-1.16.2-2.oe2403sp3.noarch.rpm"
								},
								"name":"rubygem-fluentd-1.16.2-2.oe2403sp3.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch.rpm",
									"name":"rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch.rpm"
								},
								"name":"rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"rubygem-fluentd-1.16.2-2.oe2403sp3.src.rpm",
									"name":"rubygem-fluentd-1.16.2-2.oe2403sp3.src.rpm"
								},
								"name":"rubygem-fluentd-1.16.2-2.oe2403sp3.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"rubygem-fluentd-1.16.2-2.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.noarch",
					"name":"rubygem-fluentd-1.16.2-2.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch",
					"name":"rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"rubygem-fluentd-1.16.2-2.oe2403sp3.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.src",
					"name":"rubygem-fluentd-1.16.2-2.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-44025",
			"notes":[
				{
					"text":"Fluentd's Monitor Agent plugin (`in_monitor_agent`) exposes internal metrics and plugin information via a REST API. It was discovered that the API response (`/api/plugins.json` and related endpoints) unintentionally includes internal instance variables of loaded plugins. If any plugins store sensitive information—such as database passwords, API keys, or cloud credentials—in its instance variables, this information may be exposed in plain text to any user or system that has HTTP access to the Monitor Agent API.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.src"
					],
					"details":"rubygem-fluentd security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3538"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":7.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:rubygem-fluentd-help-1.16.2-2.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:rubygem-fluentd-1.16.2-2.oe2403sp3.src"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-44025"
		}
	]
}