CVE-2025-12970 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 24, 2025
Last Seen
November 25, 2025

CVE-2025-12970 is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

CVE-2025-12970 is a vulnerability tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity November 25, 2025.

Related Threat Clusters

  • Vulnerabilities in Fluent Bit Disrupt Major Cloud Services

    A series of vulnerabilities in Fluent Bit, an open source log collection tool, were discovered by Oligo Security. These 'trivial-to-exploit' bugs, which allow attackers to bypass authentication and execute remote code,…

    4 articles · Updated November 24, 2025
  • Critical Vulnerabilities Found in Fluent Bit Logging Tool

    Fluent Bit, a widely used log-processing tool, has been found vulnerable to multiple critical security flaws that could allow attackers to bypass authentication, execute remote code, and disrupt cloud services.…

    6 articles · Updated November 25, 2025
  • Critical Vulnerabilities Found in Fluent Bit Logging Agent

    Cybersecurity researchers have identified critical vulnerabilities in Fluent Bit, a logging agent used extensively across various platforms, including banking and cloud services. The flaws could lead to authentication…

    2 articles · Updated November 24, 2025

Recent Intelligence Reports

  • Fluent Bit vulnerabilities could enable full cloud takeover — Csoonline · November 25, 2025
  • Years-old bugs in open source took out major clouds at risk — Theregister · November 24, 2025
  • Years — Theregister · November 24, 2025
  • VU#761751: fluentbit contains stack buffer overflow, authentication bypass, and path traversal flaws — Kb.Cert · November 24, 2025

Frequently asked questions

What is CVE-2025-12970?

CVE-2025-12970 is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.

Is CVE-2025-12970 still active?

The most recent intelligence report mentioning CVE-2025-12970 on ThreatCluster is dated November 25, 2025. Activity was first observed November 24, 2025, giving a tracked span from then to November 25, 2025.

What is CVE-2025-12970 associated with?

Across ThreatCluster reporting, CVE-2025-12970 most frequently co-occurs with DDoS, Denial of Service, Zero-day Exploit, Amazon Web Services, Microsoft Azure, among 12 tracked related entities.

What are the latest developments involving CVE-2025-12970?

The most significant recent cluster is “Vulnerabilities in Fluent Bit Disrupt Major Cloud Services” (4 articles · Updated November 24, 2025). CVE-2025-12970 appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on CVE-2025-12970?

CVE-2025-12970 appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown