CVE-2025-12978 Details
Description
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.
A vulnerability exists in the Fluent Bit input plugins for HTTP, Splunk, and Elasticsearch, all in version 4.1.0. The issue arises from improper validation of the tag_key, which fails to enforce precise key-length matching. This flaw allows a remote attacker with authenticated or exposed access to these input endpoints to craft inputs that manipulate tags, redirecting records to unintended destinations. As a result, the authenticity of the ingested logs is compromised, potentially leading to the injection of false data, flooding alerts, and disrupting routing processes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fluentbit.io/announcements/v4.1.0/ | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| treasuredata fluent bit | 4.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 28, 2025 | Initial Analysis | [email protected] |
| Nov 24, 2025 | CVE Modified | CISA-ADP |
| Nov 24, 2025 | New CVE Received | [email protected] |