---
id: CVE-2025-12969
title: >-
  Fluent Bit in_forward input plugin does not properly enforce the
  security.users authentication mechanism under certain configuration conditions
summary: >-
  Fluent Bit in_forward input plugin does not properly enforce the
  security.users authentication mechanism under certain configuration
  conditions. This allows remote attackers with network access to the Fluent Bit
  instance exposing the for…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-306
vendor: treasuredata
product: fluent_bit
affected:
  - fluent_bit = 4.1.0
published: '2025-11-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12969'
references:
  - url: >-
      https://fluentbit.io/blog/2025/10/28/security-vulnerabilities-addressed-in-fluent-bit-v4.1-and-backported-to-v4.0/
    label: cret@cert.org
  - url: >-
      https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover
    label: cret@cert.org
tags:
  - nvd
epss: 0.00613
epssPercentile: 0.47712
ingestedAt: '2026-10-08T10:28:22.406Z'
---

## Overview

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.

## Affected

- `fluent_bit = 4.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
