CVE Feed

    Dashboard / CVE / CVE-2025-12978

    CVE-2025-12978

    Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.

    Published:Nov 24, 2025
    Last Modified:Jan 7, 2026
    EPS:Nov 24, 2025
    EPSS Score:0.00131
    CVSS Score:5.4

    Affected Products

    Vendor
    Fluentbit
    Product
    Fluent Bit
    Vendor
    Treasuredata
    Product
    Fluent Bit

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High