CVE-2024-23722
- EPSS 0.67%
- Veröffentlicht 26.03.2024 15:15:49
- Zuletzt bearbeitet 30.04.2025 16:48:32
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
CVE-2024-26455
- EPSS 0.07%
- Veröffentlicht 26.02.2024 18:15:07
- Zuletzt bearbeitet 12.05.2025 12:57:01
fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
CVE-2021-46879
- EPSS 0.03%
- Veröffentlicht 11.04.2023 18:15:58
- Zuletzt bearbeitet 11.02.2025 20:15:31
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flb_msgpack_gelf_value_ext. An attacker can craft a malicious file and tick the victim to open the file with t...
CVE-2021-46878
- EPSS 0.04%
- Veröffentlicht 11.04.2023 18:15:58
- Zuletzt bearbeitet 11.02.2025 21:15:08
An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug that interprets whatever is on the stack as msgpack maps and arrays, leading to use-after-free. This can be us...
CVE-2021-36088
- EPSS 0.51%
- Veröffentlicht 01.07.2021 03:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:07
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
CVE-2021-27186
- EPSS 0.41%
- Veröffentlicht 10.02.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:31
Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.
CVE-2020-35963
- EPSS 0.38%
- Veröffentlicht 03.01.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:28:36
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.
CVE-2019-9749
- EPSS 1.01%
- Veröffentlicht 13.03.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:13
An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (server), it mishandles incoming network messages. After processing a crafted packet, the plugin's mqtt_packet_drop function (in /pl...