A series of "trivial-to-exploit" vulnerabilities in Fluent Bit, an open source log collection tool that runs in every major cloud and AI lab, was left open for years, giving attackers an exploit chain to completely disrupt cloud services and alter data. The Oligo Security research team found the five vulnerabilities and - in coordination with the project's maintainers - on Monday published details about the bugs that allow attackers to bypass authentication, perform path traversal, achieve remote code execution, cause denial-of-service conditions, and manipulate tags. Updating to the latest stable version, v4.1.1 / 4.0.12, fixes the flaws. Fluent Bit, an open source project maintained by Chronosphere, is used by major cloud providers and tech giants, including Google, Amazon, Oracle, IBM, and Microsoft, to collect and route data. It's a lightweight telemetry data agent and processor for logs, metrics, and traces, and it has more than 15 billion deployments. At KubeCon earlier this month, OpenAI said it runs Fluent Bit on all of its Kubernetes nodes. It's been around for 14 years, and at least one of the newly disclosed bugs, a path-traversal flaw now tracked as CVE 2025-12972, has left cloud environments vulnerable for more than 8 years, according to Oligo Security researcher Uri Katz. This, Katz told The Register, is because "the file-output behavior that makes path traversal possible has been a part of Fluent Bit since its early architecture. The other issues aren't quite a...
Years-old bugs in open source took out major clouds at risk
The Register
·Jessica Lyons
·Published Nov 24, 2025
·Updated
Affected Software
2 affected components
Chronosphere Fluent Bit=4.1.1
Chronosphere Fluent Bit=4.0.12
Frequently Asked Questions
1
What vulnerabilities are discussed in the article?
The article discusses years-old vulnerabilities in Fluent Bit that are described as 'trivial-to-exploit'.
2
What impact do these vulnerabilities have on cloud services?
These vulnerabilities allow attackers to disrupt cloud services and alter data.
3
Which software is specifically mentioned as affected by these vulnerabilities?
The affected software mentioned is Chronosphere Fluent Bit.
4
Who discovered the vulnerabilities in Fluent Bit?
The vulnerabilities were discovered by the Oligo Security research team.
5
What is the significance of these vulnerabilities being left open for years?
The prolonged exposure of these vulnerabilities increased the risk of them being exploited in major cloud and AI labs.