CVE-2025-12969

F

luent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.

Configurations

Configuration 1 (hide)

cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*

History

28 Nov 2025, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://fluentbit.io/announcements/v4.1.0/', 'tags': ['Release Notes'], 'source': '[email protected]'}
  • () https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/ -
  • () https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover -

28 Nov 2025, 15:23

Type Values Removed Values Added
First Time Treasuredata fluent Bit
Treasuredata
CPE cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*
CWE CWE-306
References () https://fluentbit.io/announcements/v4.1.0/ - () https://fluentbit.io/announcements/v4.1.0/ - Release Notes

24 Nov 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

24 Nov 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 15:15

Updated : 2025-11-28 18:15


NVD link : CVE-2025-12969

Mitre link : CVE-2025-12969

CVE.ORG link : CVE-2025-12969


JSON object : View

Products Affected
CWE
CWE-306

Missing Authentication for Critical Function