Cyber Resilience

CVE-2025-12978

Treasuredata Fluent Bit 4.1.0

Published
24 November 2025
Modified
28 November 2025
CVSS Score v3.1 5.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS Score 0.0038 31th percentile
Risk Priority 43 floored blend · peak EPSS

Summary

CVE-2025-12978 is a medium-severity an unspecified weakness vulnerability in Treasuredata Fluent Bit. Its CVSS base score is 5.4 (Medium).

Operationally, ranked at the 31th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote…

more

attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-12977Same product: Treasuredata Fluent Bit
CVE-2025-12969Same product: Treasuredata Fluent Bit
CVE-2024-4323Same product: Treasuredata Fluent Bit
CVE-2024-23722Same product: Treasuredata Fluent Bit
CVE-2025-29477Same product: Treasuredata Fluent Bit
CVE-2025-12970Same product: Treasuredata Fluent Bit
CVE-2024-50608Same product: Treasuredata Fluent Bit
CVE-2025-29478Same product: Treasuredata Fluent Bit
CVE-2024-26455Same product: Treasuredata Fluent Bit
CVE-2024-50609Same product: Treasuredata Fluent Bit

Affected Assets

treasuredata
fluent bit
4.1.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References