PT-2025-47923 · Unknown+2 · Fluent Bit In Http Input Plugin+6
Published
2025-11-24
·
Updated
2026-03-19
·
CVE-2025-12977
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Bit versions (affected versions not specified)
Description
The in http, in splunk, and in elasticsearch input plugins in Fluent Bit do not properly sanitize
tag key inputs. An attacker who can access the network or write records to Splunk or Elasticsearch can use special characters like newlines or '../' within tag key values. These characters are interpreted as valid tags, potentially leading to newline injection, path traversal, forged record injection, or incorrect log routing, which compromises data integrity and log routing. The tag key variable is used to influence routing and can affect filenames or content in some outputs.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch
Fluent-Bit
Fluent Bit In Elasticsearch Input Plugin
Fluent Bit In Http Input Plugin
Fluent Bit In Splunk Input Plugin
Red Os
Splunk