Hi users!
We have released fluent-package v6.0.5 on 2026-09-29. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)
This is a maintenance release of v6.0.x LTS series.
Fluent Package v6.0.5 includes the following improvements:
oj, json)This article explains the changes in Fluent Package v6.0.5.
In this release, some critical vulnerabilities were fixed.
.. Tag in Output Plugins
${tag} placeholder in the path parameter of output plugins. Filter incoming untrusted tags.in_http ndjson parsing
in_http, allow connection within a closed, trusted network. Implement reverse proxy limits with forcing strict rate limiting and request size limits at the proxy layer to drop anomalous requests before they reach the Fluentd worker.in_syslog
in_syslog, allow connection within a closed, trusted network. Switch to UDP Transport for a while. Implement reverse proxy limits with strict client connection timeout and buffer size limits to terminate anomalous, non-delimited streams before they overwhelm Fluentd.disable_chunk_backup true. Restrict incoming data only within a closed, trusted network.The above vulnerabilities affects to older than v1.19.4, thus the following packages also will be affected.
We recommend upgrading fluent-package to v6.0.5.
If you can't upgrade it immediately, there is a case that mitigation method is explained in above advisory. Please check each advisory and take care of it.
Fluentd v1.19.4 also contains many bug fixes. See the release announcement of Fluentd v1.19.4 for details.
Ruby 3.4.11 is a maintenance release. Compared to Ruby 3.4.9 which was bundled in the previous version, it includes the following security fixes in bundled gems:
net-imap: CVE-2026-47240, CVE-2026-47241, CVE-2026-47242 (fixed in Ruby 3.4.10)resolv: CVE-2026-80212 and CVE-2026-80213 (fixed in Ruby 3.4.11)For details, please see the Ruby 3.4.10 and Ruby 3.4.11 release notes.
The link to the enterprise services page on the popup window of the Windows installer was broken. It has been fixed in this release. (#1079)
The packages for RHEL 9.x and 10.x were built on the latest minor version of each series.
As a result, the built binaries required newer symbols such as GLIBC_2.35 or OPENSSL_3.4.0,
and they did not work on older minor versions like RHEL 9.6 or RHEL 10.1.
To keep the ABI compatible in the whole 9.x and 10.x series, the build environment is now pinned to RHEL 9.2 and RHEL 10.0. (#1089, #1090)
This issue was fixed and shipped as 6.0.4-2 on above platforms which had been implemented in advance, has now been officially released.
RPM 4.19 (AlmaLinux 10) and dpkg-buildflags on Ubuntu export LTO (Link Time Optimization) flags
(-flto=auto -ffat-lto-objects) into the build process. These flags leaked into jemalloc, Ruby and
native gem extensions, and made the build much slower. For example, the total build time on AlmaLinux 10
grew extraordinaly.
Since the bundled Ruby uses its own optimization settings, LTO gives no measurable benefit here.
So we removed the LTO flags and the annobin plugin from the build environment.
The hardening flags such as stack protection, control flow protection and FORTIFY_SOURCE are kept as before.
This change also means that native extensions which users build with fluent-gem install no longer
inherit the LTO overhead. (#1102)
Please visit the download page.
We plan to release the next LTS version of fluent-package v6.0.6 at Dec 2026. The content of updates are still TBD.
We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.
Subscribed to the RSS feed here.
ClearCode, Inc. is a software company specializing in the development of Free Software. We maintain Fluentd and its plugin ecosystem, and provide commercial support for them.
Fluentd is an open source data collector to unify log management.
2026-08-14: Scheduled support lifecycle announcement about Fluent Package v7
2025-12-25: Drop schedule announcement about EOL of Fluent Package (fluent-package) 5
2025-09-04: Upgrade Guide for fluent-package v6
2024-08-29: Scheduled support lifecycle announcement about Fluent Package v6
2023-08-29: Drop schedule announcement about EOL of Treasure Agent (td-agent) 4
2023-08-29: Scheduled support lifecycle announcement about Fluent Package
2023-07-31: Upgrade to fluent-package v5
2026-09-29: Fluentd v1.19.4 has been released
2026-09-29: fluent-package v6.0.5 has been released
2026-08-14: Scheduled support lifecycle announcement about Fluent Package v7
2026-06-26: fluent-package v6.0.4 has been released
2026-06-25: Fluentd v1.19.3 has been released
2026-03-27: fluent-package v6.0.3 has been released
2026-02-27: fluent-package v6.0.2 has been released
2026-02-13: Fluentd v1.19.2 has been released
2025-12-25: Drop schedule announcement about EOL of Fluent Package (fluent-package) 5
2025-12-19: fluent-package v5.0.9 has been released
Want to learn the basics of Fluentd? Check out these pages.
Couldn't find enough information? Let's ask the community!
You need commercial-grade support from Fluentd committers and experts?
©2010-2026 Fluentd Project. ALL Rights Reserved.
Fluentd is a hosted project under the Cloud Native Computing Foundation (CNCF). All components are available under the Apache 2 License.
The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page, Privacy Policy and Terms of Use.