CVE-2025-12972
CVE-2025-12972 is a medium-severity vulnerability in Treasuredata Fluent Bit with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 1% (52nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-198810
- Weakness: CWE-22
- Affected product: Treasuredata Fluent Bit
- Published:
- Last modified:
Description
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.
Frequently asked questions
- What is CVE-2025-12972?
- Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.
- How severe is CVE-2025-12972?
- CVE-2025-12972 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2025-12972 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (52nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-12972?
- CVE-2025-12972 affects Treasuredata Fluent Bit. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-12972?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-12972 have an EU (EUVD) identifier?
- Yes. CVE-2025-12972 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-198810.
- When was CVE-2025-12972 published?
- CVE-2025-12972 was published on 2025-11-24 and last updated on 2026-06-17.
References
- https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/
- https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover
Affected products (1)
- cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*
More vulnerabilities in Treasuredata Fluent Bit
- CVE-2024-4323 — Critical (CVSS 9.8): A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http…
- CVE-2021-36088 — Critical (CVSS 9.8): Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and…
- CVE-2025-12977 — Critical (CVSS 9.1): Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with…
- CVE-2025-12970 — High (CVSS 8.8): The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer…
- CVE-2021-46879 — High (CVSS 7.8): An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting…
- CVE-2021-46878 — High (CVSS 7.8): An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads…
All CVEs affecting Treasuredata Fluent Bit →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.