Fluent Bit Tag Manipulation Vulnerability in Input Plugins

Vulnerability

A vulnerability exists in the Fluent Bit input plugins for HTTP, Splunk, and Elasticsearch, all in version 4.1.0. The issue arises from improper validation of the tag_key, which fails to enforce precise key-length matching. This flaw allows a remote attacker with authenticated or exposed access to these input endpoints to craft inputs that manipulate tags, redirecting records to unintended destinations. As a result, the authenticity of the ingested logs is compromised, potentially leading to the injection of false data, flooding alerts, and disrupting routing processes.

Impact

Exploitation of this vulnerability could result in unauthorized manipulation of log tags, allowing for misdirection of log records and injection of fraudulent data into the system. This could create a false sense of activity through alert flooding and disrupt normal log routing processes, causing potential oversight of critical events.

Added: Nov 24, 2025, 3:17 PM
Updated: Nov 24, 2025, 4:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.