ThreatCluster

Two CVEs Identified in Fluent-Bit v3.7.2 Allow Local Denial of Service Attacks

First seen 6 Dec 2025, 22:50 UTC Api.Msrc.Microsoft 85% similarity 33

Article Content

Browse articles
ThreatCluster

CVE-2025-29478 and CVE-2025-29477 are vulnerabilities in fluent-bit version 3.7.2 that allow local attackers to cause a denial of service. The first issue relates to the cfl_list_size in cfl_list.h:165, while the second involves the consume_event function. Both vulnerabilities have been documented by Microsoft.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story