---
id: CVE-2025-12978
title: >-
  Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a
  flaw in the tag_key validation logic that fails to enforce exact key-length
  matching
summary: >-
  Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a
  flaw in the tag_key validation logic that fails to enforce exact key-length
  matching. This allows crafted inputs where a tag prefix is incorrectly treated
  as a f…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
vendor: treasuredata
product: fluent_bit
affected:
  - fluent_bit = 4.1.0
published: '2025-11-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12978'
references:
  - url: 'https://fluentbit.io/announcements/v4.1.0/'
    label: cret@cert.org
tags:
  - nvd
epss: 0.00393
epssPercentile: 0.31338
ingestedAt: '2026-10-08T10:28:22.460Z'
---

## Overview

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.

## Affected

- `fluent_bit = 4.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
