Hi users!
We have released v1.19.4 on 2026-09-29. ChangeLog is here.
This release is a maintenance release of v1.19 series.
This release will be bundled for fluent-package LTS version v6.0.5!
Many vulnerabilities were fixed in this release.
.. Tag in Output Plugins
${tag} placeholder in the path parameter of output plugins. Filter incoming untrusted tags.in_http ndjson parsing
in_http, allow connection within a closed, trusted network. Implement reverse proxy limits with forcing strict rate limiting and request size limits at the proxy layer to drop anomalous requests before they reach the Fluentd worker.in_syslog
in_syslog, allow connection within a closed, trusted network. Switch to UDP Transport for a while. Implement reverse proxy limits with strict client connection timeout and buffer size limits to terminate anomalous, non-delimited streams before they overwhelm Fluentd.disable_chunk_backup true. Restrict incoming data only within a closed, trusted network.In most cases, there is no problem using deployed Fluentd within a closed, trusted network. If you could not update Fluentd immediately, consider to take advised mitigation in above advisories.
Many bugs were also fixed in this release.
output: fix JSON::GeneratorError as unrecoverable error. (#5423)
allow_duplicate_key parameter for JSON.parse. It accept duplicate keys silently
(last value wins) on every path. It keeps compatibility with older versions even though
newer json gem is used. (#5430)allow_comments parameter for JSON.parse. It accepts JSON with comments.
It keeps compatibility with older versions even though newer json gem is used. (#5432)parser_syslog: Optimize RFC5424 structured data parsing (#5444)
out_forward: drop keepalive sockets with failed or mismatched acks (#5445)
buffer: fix stage_byte_size leak when a staged chunk is unstaged (#5456)
BufferOverflowError.
It affects plugins which implementing #format.plugin base: bound the number of worker lock files by hashing the path into a fixed set of buckets. (#5471)supervisor: reduce memory usage of cleanup_lock_dir with huge number of lock files (#5472)config: accept empty lines in quoted strings (#5478)chunk: ensure to close the Tempfile for decompressed data (#5486)buffer: fix spurious BufferOverflowError caused by queue_size leaking when a chunk purge fails (#5487)buffer: clamp exported buffer size metrics to non-negative values (#5488)parser_syslog: fix NameError when RFC3164 timestamp has repeated spaces (#5497)parser_syslog: fix NameError when RFC5424 timestamp has repeated spaces (#5500)In the previous versions, a single scalar value for an array option is rejected in YAML config syntax.
Since v1.19.4, it accepts the following example.
config:
- match:
$tag: "**"
$type: http
retryable_response_codes: 503
When workers > 1, out_file (with append) and
out_secondary_file take an inter-worker lock per output path, and
get_lock_path derives one lock file per path:
/tmp/fluentd-lock-*/fluentd-<sanitized path>.lock.
In the previous versions, a lock file is never removed while fluentd
is running; the only cleanup is cleanup_lock_dir at a graceful
shutdown. So the number of lock files grows with the number of unique
output paths, and with a date or a tag placeholder in path that set
is effectively unbounded over time.
In this release, the number of lock files is now bounded by a constant instead of by the number of unique paths. The accumulation, the mass deletion at shutdown, and the dependence on an external tmp cleaner all disappear structurally rather than being mitigated.
Enjoy logging!
We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.
Subscribed to the RSS feed here.
ClearCode, Inc. is a software company specializing in the development of Free Software. We maintain Fluentd and its plugin ecosystem, and provide commercial support for them.
Fluentd is an open source data collector to unify log management.
2026-08-14: Scheduled support lifecycle announcement about Fluent Package v7
2025-12-25: Drop schedule announcement about EOL of Fluent Package (fluent-package) 5
2025-09-04: Upgrade Guide for fluent-package v6
2024-08-29: Scheduled support lifecycle announcement about Fluent Package v6
2023-08-29: Drop schedule announcement about EOL of Treasure Agent (td-agent) 4
2023-08-29: Scheduled support lifecycle announcement about Fluent Package
2023-07-31: Upgrade to fluent-package v5
2026-09-29: Fluentd v1.19.4 has been released
2026-09-29: fluent-package v6.0.5 has been released
2026-08-14: Scheduled support lifecycle announcement about Fluent Package v7
2026-06-26: fluent-package v6.0.4 has been released
2026-06-25: Fluentd v1.19.3 has been released
2026-03-27: fluent-package v6.0.3 has been released
2026-02-27: fluent-package v6.0.2 has been released
2026-02-13: Fluentd v1.19.2 has been released
2025-12-25: Drop schedule announcement about EOL of Fluent Package (fluent-package) 5
2025-12-19: fluent-package v5.0.9 has been released
Want to learn the basics of Fluentd? Check out these pages.
Couldn't find enough information? Let's ask the community!
You need commercial-grade support from Fluentd committers and experts?
©2010-2026 Fluentd Project. ALL Rights Reserved.
Fluentd is a hosted project under the Cloud Native Computing Foundation (CNCF). All components are available under the Apache 2 License.
The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page, Privacy Policy and Terms of Use.