https://seclists.org/oss-sec/2025/q4/207: 5 CVE's fixed in Fluent Bit
Published Nov 26, 2025
·Updated
Affected Software
1 affected component
Fluent Bit Fluent Bit
Frequently Asked Questions
1
What is the severity of CVE-2025-12972?
CVE-2025-12972 has been classified with a critical severity rating due to the potential for remote takeover.
2
How do I fix CVE-2025-12972?
To fix CVE-2025-12972, update Fluent Bit to the latest version where the vulnerability has been patched.
3
What does CVE-2025-12972 exploit?
CVE-2025-12972 exploits unsanitized tag values used in generating output filenames, leading to path traversal vulnerabilities.
4
Which versions of Fluent Bit are affected by CVE-2025-12972?
CVE-2025-12972 affects all versions of Fluent Bit prior to the patched release that addresses this vulnerability.
5
What are the potential impacts of CVE-2025-12972?
The potential impacts of CVE-2025-12972 include unauthorized access and modification of files, compromising the security of cloud environments.