CVE-2025-12969 describes an authentication bypass vulnerability in the Fluent Bit in_forward input plugin, specifically affecting treasuredata fluent_bit. Under certain configurations, the security.users authentication mechanism is not properly enforced, allowing remote, unauthenticated attackers to send data. This medium-severity vulnerability (CVSS 6.5) permits the injection of forged log records, flooding of alerting systems, or manipulation of routing decisions, compromising log authenticity and integrity. There is no evidence of active exploitation, nor are there public exploit codes like Metasploit or Nuclei modules; however, the vulnerability has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.