PT-2026-96148 · Unknown · Fluent-Bit

CVE-2026-61674

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Fluent Bit versions 0.11.0 through 5.0.7
Description A stack buffer overflow exists in the secure forward pong function within plugins/out forward/forward.c. The issue occurs when the software copies a server-controlled PONG reason into a 32-byte stack buffer msg using memcpy without verifying the MessagePack type or length. An attacker who controls or impersonates a Secure Forward destination configured with Shared Key or Empty Shared Key can send an oversized reason during the initial handshake to overwrite stack control data. This can result in the termination of protected builds or remote code execution as the Fluent Bit process user in builds lacking a stack canary or those with a memory disclosure. When using the --supervisor mode, fork-only respawns preserve the canary and address layout, potentially facilitating repeated probes to achieve code execution on hardened builds.
Recommendations Update to version 5.0.8 or later. Audit every out forward Shared Key destination.

Exploit

Fix

RCE

Stack Overflow

Memory Corruption

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-FLUENT-BIT-2026-61674
CVE-2026-61674
GHSA-JRP8-R9HX-GF73

Affected Products

Fluent-Bit