VendorsTreasuredatafluent_bitall versions
Vulnerabilities

Treasuredata Fluent Bit

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2024-4323
Fluent Bit Memory Corruption Vulnerability
Published 2024-05-20 · Analyzed
9.8EPSS 0.272
CVE-2021-36088
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
Published 2021-07-01 · Modified
9.8EPSS 0.024
CVE-2025-12977
CVE-2025-12977
Published 2025-11-24 · Modified
9.1EPSS 0.007
CVE-2025-12970
CVE-2025-12970
Published 2025-11-24 · Modified
8.8EPSS 0.010
CVE-2020-35963
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
Published 2021-01-03 · Modified
7.8EPSS 0.013
CVE-2021-46879
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flb_msgpack_gelf_value_ext. An attacker can craft a malicious file and tick the victim to open the file with the software, triggering a heap overflow and execute arbitrary code on the target system.
Published 2023-04-11 · Modified
7.8EPSS 0.004
CVE-2021-46878
An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug that interprets whatever is on the stack as msgpack maps and arrays, leading to use-after-free. This can be used by an attacker to craft a specially craft file and trick the victim opening it using the affect software, triggering use-after-free and execute arbitrary code on the target system.
Published 2023-04-11 · Modified
7.8EPSS 0.004
CVE-2021-27186
Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.
Published 2021-02-10 · Modified
7.5EPSS 0.020
CVE-2019-9749
An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (server), it mishandles incoming network messages. After processing a crafted packet, the plugin's mqtt_packet_drop function (in /plugins/in_mqtt/mqtt_prot.c) executes the memmove() function with a negative size parameter. That leads to a crash of the whole Fluent Bit server via a SIGSEGV signal.
Published 2019-03-13 · Modified
7.5EPSS 0.017
CVE-2024-50608
An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_metrics_ng() at prom_rw_prot.c.
Published 2025-02-18 · Analyzed
7.5EPSS 0.011
CVE-2024-50609
An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_traces_proto_ng() at opentelemetry_prot.c.
Published 2025-02-18 · Analyzed
7.5EPSS 0.011
CVE-2024-23722
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
Published 2024-03-26 · Analyzed
7.5EPSS 0.009
CVE-2024-26455
fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
Published 2024-02-26 · Analyzed
7.5EPSS 0.007
CVE-2025-12969
CVE-2025-12969
Published 2025-11-24 · Modified
6.5EPSS 0.006
CVE-2025-29478
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
Published 2025-04-07 · Analyzed
5.5EPSS 0.002
CVE-2025-29477
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
Published 2025-04-04 · Analyzed
5.5EPSS 0.002
CVE-2025-12978
CVE-2025-12978
Published 2025-11-24 · Analyzed
5.4EPSS 0.004
CVE-2025-12972
CVE-2025-12972
Published 2025-11-24 · Modified
5.3EPSS 0.009