Impact
Uncontrolled Resource Consumption (CWE-400) allows an authenticated, low‑privilege user to trigger a denial of service by sending a specially crafted, oversized request payload to Kibana. The request forces the server to allocate large amounts of memory, exhausting the available heap and causing the Kibana process to crash, which makes the service unavailable to all users.
Affected Systems
Elastic Kibana is impacted. The specific affected versions are not listed, so all installations of Kibana that are reachable by authenticated users should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is reported as less than 1%, suggesting a low likelihood of exploitation and it is not listed in CISA’s KEV catalog. It requires authenticated low‑privilege access and relies on sending a large request body; exploitation is therefore limited to users who can authenticate to the application.
OpenCVE Enrichment