CVE-2025-12977CRITICAL 9.1EPSS p44.4%

CVE-2025-12977CVE-2025-12977

Description

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.61% probability of exploitation · percentile 44.4% · 2026-06-19T12:03:05Z
Published2025-11-24
Last modified2025-11-28

Underlying weaknesses· 1

CWE-1287

References

  1. https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/
  2. https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover

1

TypeTargetConfidenceTier
WeaknessImproper Validation of Specified Type of Inputcwe-12870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-12970
CVE
CVE-2025-59171
CVE
CVE-2025-64128
CVE
CVE-2025-64127
CVE
CVE-2025-64126
CVE
CVE-2026-5027
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.