Impact
Incorrect handling of heavily compressed data in Kibana can cause a denial of service by forcing the process to allocate an excessive amount of memory, eventually leading to termination of the Kibana service.
Affected Systems
The vulnerability affects Kibana provided by Elastic. No specific version range is listed, so all releases before the next security update could potentially be susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is not available, suggesting no known public exploitation at this time. The exploit requires an authenticated user with streams‑management privileges to supply crafted data, so it is not a remote code‑execution vulnerability but can disrupt service availability for all users until the process is restarted.
OpenCVE Enrichment