Impact
A flaw in Kibana allows an attacker to supply an unbounded, non‑deduplicated list of document fields to the Kibana Playground’s RAG feature, causing the system to assemble an excessively large response. The resulting memory consumption can exhaust the instance’s resources, leading to degraded performance or a complete denial of service. The weakness is classified as CWE‑770, allocating resources without limits.
Affected Systems
The vulnerability affects Elastic Kibana, currently without a specific version listed in the CVE data. No affected version information is provided, so any deployment of this product should assume the risk until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting the exploitation likelihood is unclear. The attack vector is inferred to be via an HTTP request to the Kibana Playground, where a crafted payload can trigger the memory exhaustion without additional privileges.
OpenCVE Enrichment