# CVE-2024-4323

## Summary

- **CVE ID:** CVE-2024-4323
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-122
- **Published:** May 20, 2024
- **Last Modified:** Mar 13, 2026

## Description

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

## Affected Products

- Fluent Bit — Fluent Bit (2.0.7)

## References

- [CNA](https://tenable.com/security/research/tra-2024-17)
- [CNA](https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04)
- [CVE](https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 27.24%
- **EPSS Percentile:** 97.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._