Five critical vulnerabilities were discovered in Fluent Bit, a widely used open-source telemetry and log collection agent deployed across major cloud providers and AI labs. These flaws, some of which have existed for years, allow attackers to bypass authentication, perform path traversal, achieve remote code execution, cause denial-of-service, and manipulate log tags. The vulnerabilities, identified by Oligo Security, affect all major cloud platforms and have the potential to disrupt cloud services, alter or tamper with data, and enable deeper intrusions into cloud and Kubernetes infrastructure. Fluent Bit is used by tech giants such as Google, Amazon, Oracle, IBM, Microsoft, and OpenAI, with over 15 billion deployments worldwide.
The vulnerabilities include CVE-2025-12972 (path traversal via unsanitized tag values), CVE-2025-12970 (stack buffer overflow in the Docker Metrics input plugin), CVE-2025-12978 (tag-matching logic spoofing), CVE-2025-12977 (improper input validation of tags), and CVE-2025-12969 (missing authentication in the in_forward plugin). Exploiting these flaws could allow attackers to write or overwrite arbitrary files, inject malicious records, reroute logs, and flood security products with false events. The issues have been addressed in Fluent Bit versions v4.1.1 and 4.0.12, and users are urged to update immediately to mitigate risk.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
An oss-sec mailing list post summarized the five newly disclosed Fluent Bit CVEs, including path traversal, stack buffer overflow, tag spoofing, sanitization bypass, and authentication disablement issues. The post also cited Fluent Bit's advisory stating the vulnerabilities were fixed in v4.2 and v4.1.1 and backported to v4.0.14.
Coordinated disclosure involved AWS, and CERT/CC noted that several of the flaws require network access to a Fluent Bit instance and could lead to authentication bypass, RCE, service disruption, and tag spoofing. AWS advised customers using Fluent Bit to update to patched versions.
Oligo Security disclosed five long-standing vulnerabilities in Fluent Bit that can enable authentication bypass, tag manipulation, path traversal, denial of service, and potential remote code execution. The researchers warned the bugs could be chained to tamper with logs, overwrite files, and compromise cloud and Kubernetes environments.
Fluent Bit addressed five security flaws in stable releases published last month, with fixes available in versions 4.1.1 and 4.0.12 according to coordinated disclosure reporting. A later advisory and oss-sec post indicated the fixes were also present in v4.2 and backported to v4.0.14.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.