CVE-2021-36088
CRITICALFluent Bit <1.7.5 - Memory Corruption
Title source: llmDescription
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
66.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
Status
published
Affected Products (1)
treasuredata/fluent_bit
< 1.7.4
Timeline
Published
Jul 01, 2021
Tracked Since
Feb 18, 2026