OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77619

HIGH · CVSS 8.7 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects the logstash source of the Vector observability data pipeline, allowing an unauthenticated remote attacker to exploit a flaw in buffer allocation by sending a crafted frame with a misleadingly large payload size. This can lead to excessive memory allocation, potentially causing the application to crash or triggering the host's Out-Of-Memory (OOM) killer, disrupting log ingestion for all tenants in a shared environment. Organizations using affected versions (0.15.0 to 0.57.0) should prioritize patching to version 0.57.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77619
Severity
HIGH
CVSS
8.7
EPSS
0.52%

Original NVD Description

Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a minimal frame declaring a multi-gigabyte payload, causing an excessive allocation that can abort Vector or invoke the host OOM killer. Because the allocation follows the declared length rather than bytes transmitted, the attacker has low resource cost, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0.