CVE-2025-12969
MEDIUMFluent Bit - Unauthenticated Log Injection via in_forward Input Plugin
Title source: llmDescription
Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.
References (2)
Core 2
Scores
CVSS v3
6.5
EPSS
0.0053
EPSS Percentile
40.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
treasuredata/fluent_bit
4.1.0
Published
Nov 24, 2025
Tracked Since
Feb 18, 2026