OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77620

HIGH · CVSS 8.7 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects the logstash source of Vector, allowing unauthenticated remote peers to exploit unlimited nested compression depth, leading to a stack exhaustion that can crash the process. This results in halted log ingestion for all tenants on a shared pipeline, significantly impacting observability and data collection. Organizations using versions 0.15.0 to 0.57.0 should prioritize upgrading to version 0.57.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77620
Severity
HIGH
CVSS
8.7
EPSS
0.52%

Original NVD Description

Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send many nested compressed frames, causing recursive decoding that exhausts the worker thread stack and aborts the process. The same nested construction amplifies decompressed input, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0.