Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-4323

48
FAUCET Score

CVE-2024-4323 is a critical memory corruption vulnerability affecting Fluent Bit versions 2.0.7 through 3.0.3, stemming from improper handling of trace requests in its embedded HTTP server. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication and can lead to denial of service, information disclosure, or remote code execution. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community attention and media coverage due to its widespread impact on major cloud providers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.7, < 2.2.3CPE matchmatch criteria
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.4CPE matchmatch criteria
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
28.31%
Probability of exploitation in next 30 days
EPSS Percentile
97.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.2831 is in the 95th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

3cxpatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 fluent-bit 2.2.3-7 on CBL Mariner 2.0Fixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.2.3-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: 17326-16823Fixed in: 2.2.3-1
microsoftpatch availablevia msrc
Product: azl3 fluent-bit 3.0.3-1 on Azure Linux 3.0Fixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.2.3-1
microsoftpatch availablevia msrc
Product: 17732-17084Fixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: 17813-17084Fixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: 20061-17086Fixed in: 3.0.6-1
microsoftpatch availablevia msrc
Product: cbl2 fluent-bit 2.2.3-1 on CBL Mariner 2.0Fixed in: 2.2.3-1
microsoftpatch availablevia msrc
Product: azl3 fluent-bit 3.0.6-1 on Azure Linux 3.0Fixed in: 3.0.6-1
samrocketmanpatch availablevia llm_extracted
View patch
ranchervendor investigatingvia llm_extracted

Vendor Advisories (5)

microsoft2024-Nov/CVE-2024-4323

CVE-2024-4323

Nov 12, 2024
samrocketmanllm-samrocketman-3d02397453136c7fHIGH

NR24-01

Jun 8, 2024
3cxllm-3cx-d232e6b1f5c60f7cHIGH

NR24-01

Jun 8, 2024
rancherllm-rancher-351436e8e7d2c997CRITICAL

Fluent Bit Memory Corruption Vulnerability

May 17, 2024
microsoft2024-May/CVE-2024-4323Critical

Fluent Bit Memory Corruption Vulnerability

May 14, 2024

References

vicarius.io / vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323
ExploitThird Party Advisory
github.com / fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04
Patch
tenable.com / security/research/tra-2024-17
PatchThird Party Advisory