Where
-Infinity
0

Vendor Risk Score

See how fluent compares to other vendors in security performance

View Risk Score →
Severity
9.8
Malicious File Upload
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the setfeaturedimagefromexternalurl() function in all versions up to, and including, 1.1.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible in configurations where unauthenticated users have been provided with a method for adding featured images, and the workflow trigger is created.

First published (updated )
Severity
7.5
Null Pointer Dereference
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cflsdslen, which in turn tries to cast a NULL pointer into struct cflsds. This is related to processpayloadtracesprotong() at opentelemetryprot.c.

First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVE-2025-12969

1 / 2
Source: Microsoft
First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with subscriber level access and above, to import arbitrary calendars and manage them.

First published (updated )
Severity
4
Command Injection

Escape sequence injection vulnerability in the filterparser.rb:filterstream function of Fluentd versions 0.12.29 through 0.12.40 may allow for unescaped arbitrary command injection to log files and terminal output.

Processing a specially crafted log may allow for arbitrary command exectuion on the device collecting logs.

References: https://nvd.nist.gov/vuln/detail/CVE-2017-10906 https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes https://github.com/fluent/fluentd/pull/1733 https://jvn.jp/en/vu/JVNVU95124098/index.html

First published (updated )

Hello,

On 12/1/25 9:15 PM, Christian Brabandt wrote: On Mi, 26 Nov 2025, Alan Coopersmith wrote: https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/ provides their analysis and information about fixes in versions 4.2, 4.1.1, and 4.0.14, which are available from https://github.com/fluent/fluent-bit . For the record, there is a typo in the above blog post. The backported fixed version is v4.0.13

1. [1] lists 4.2, 4.1.1 and 4.0.14 as fixes 2. [2] lists 4.0.12, 4.1.1 and 4.2.0 as fixes 3. In this thread 4.0.13 (among 4.1.1 and 4.2.0) is now listed as a fix Regards, [2] https://kb.cert.org/vuls/id/761751 [3] https://github.com/fluent/fluent-bit/releases

On 12/2/25 4:56 PM, Christian Brabandt wrote: Well, I have asked upstream https://github.com/fluent/fluent-bit/issues/11230 and they have confirmed and updated the blog post[1] to mention 4.0.13 as the proper backported fix.

I did not check or even verify the other versions. Thanks a lot for the reference, this was a missing link so far. https://github.com/fluent/fluent-bit/issues/11230#issuecomment-3606609133

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203