CVE-2025-12977 is a critical vulnerability in Fluent Bit's in_http, in_splunk, and in_elasticsearch input plugins, affecting treasuredata fluent_bit. It allows attackers with network access or the ability to write records to Splunk or Elasticsearch to inject malicious tag_key values. This can lead to newline injection, path traversal, forged record injection, or log misrouting, severely impacting data integrity and log routing. With a CVSS score of 9.1 (CRITICAL) and a FAUCET Risk Score of 90/100, the vulnerability is easily exploitable over the network without authentication or user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating a high level of awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.