SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78588

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Filebeat is vulnerable to a denial of service due to improper resource allocation, allowing an attacker to exploit the HTTP ingestion endpoint by sending specially crafted compressed requests. This can lead to excessive memory consumption, potentially crashing the Filebeat process. Organizations using Filebeat should prioritize addressing this vulnerability to prevent service disruptions.

CVE
CVE-2026-78588
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)