High severity7.5NVD Advisory· Published Feb 10, 2021· Updated Jun 17, 2026
CVE-2021-27186
CVE-2021-27186
Description
Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:treasuredata:fluent_bit:1.6.10:*:*:*:*:*:*:*
- Fluent Bit/Fluent Bitdescription
- Range: <1.6.10
Patches
Vulnerability mechanics
References
3- github.com/fluent/fluent-bit/pull/3047nvdPatchThird Party Advisory
- github.com/fluent/fluent-bit/issues/3044nvdExploitThird Party Advisory
- github.com/fluent/fluent-bit/pull/3045nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.