Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-12977 Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to … Fluent Bit Mitigation only Fix from $2,3002025-11-24 HIGH 8.8 CVE-2025-12970 The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length. An at… Fluent Bit Mitigation only Fix from $1,9502025-11-24 MEDIUM 6.5 CVE-2025-12969 Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This… Fluent Bit Mitigation only Fix from $1,6002025-11-24 MEDIUM 5.4 CVE-2025-12978 Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-leng… Fluent Bit Mitigation only Fix from $1,6002025-11-24 MEDIUM 5.3 CVE-2025-12972 Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses un… Fluent Bit Mitigation only Fix from $1,6002025-11-24 MEDIUM 5.5 CVE-2025-29478 An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165. Fluent Bit No fix yet Fix from $1,6002025-04-07 MEDIUM 5.5 CVE-2025-29477 An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event. Fluent Bit No fix yet Fix from $1,6002025-04-04 HIGH 7.5 CVE-2024-50608 An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one ca… Fluent Bit No fix yet Fix from $1,9502025-02-18 HIGH 7.5 CVE-2024-50609 An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a p… Fluent Bit No fix yet Fix from $1,9502025-02-18 HIGH 7.5 CVE-2024-26455 fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c. Fluent Bit No fix yet Fix from $1,9502024-02-26