Skip to content
ThreatCluster

Two CVEs Identified in Fluent-Bit v3.7.2 Allow Local Denial of Service Attacks

First seen 6 Dec 2025, 22:50 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

CVE-2025-29478 and CVE-2025-29477 are vulnerabilities in fluent-bit version 3.7.2 that allow local attackers to cause a denial of service. The first issue relates to the cfl_list_size in cfl_list.h:165, while the second involves the consume_event function. Both vulnerabilities have been documented by Microsoft.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2025-29477 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed