VendorsTreasuredatafluent_bitany version
Vulnerabilities

Treasuredata Fluent Bit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-4323
Fluent Bit Memory Corruption Vulnerability
Published 2024-05-20 · Analyzed
9.8EPSS 0.272
CVE-2021-36088
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
Published 2021-07-01 · Modified
9.8EPSS 0.024
CVE-2020-35963
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
Published 2021-01-03 · Modified
7.8EPSS 0.013
CVE-2019-9749
An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (server), it mishandles incoming network messages. After processing a crafted packet, the plugin's mqtt_packet_drop function (in /plugins/in_mqtt/mqtt_prot.c) executes the memmove() function with a negative size parameter. That leads to a crash of the whole Fluent Bit server via a SIGSEGV signal.
Published 2019-03-13 · Modified
7.5EPSS 0.017
CVE-2024-23722
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
Published 2024-03-26 · Analyzed
7.5EPSS 0.009
CVE-2025-29478
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
Published 2025-04-07 · Analyzed
5.5EPSS 0.002
CVE-2025-29477
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
Published 2025-04-04 · Analyzed
5.5EPSS 0.002