Two CVEs Identified in Fluent-Bit v3.7.2 Allow Local Denial of Service Attacks
First seen 6 Dec 2025, 22:50 UTC
•
•85% similarity
•33
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
CVE-2025-29478 and CVE-2025-29477 are vulnerabilities in fluent-bit version 3.7.2 that allow local attackers to cause a denial of service. The first issue relates to the cfl_list_size in cfl_list.h:165, while the second involves the consume_event function. Both vulnerabilities have been documented by Microsoft.
ThreatCluster AI
How this analysis works