216.73.217.22

CVE-2025-12977

· Published 24/11/2025 15:15 · Modified 28/11/2025 18:15

Labels: CVE-2025-12977 2025-11-24CVE-2025-12977CWE-1287[email protected]

Essential information

Published
24/11/2025 15:15
Modified
28/11/2025 18:15
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.

NVD status

Status
Modified — CVE has been amended by a source (CVE Primary CNA or another CNA). Analysis data supplied by the NVD may be no longer be accurate due to these changes.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
treasuredata / fluent bit cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*

References