Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.
Published: 2026-09-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Filebeat has a resource allocation flaw that allows an attacker to send numerous specially crafted compressed requests to its HTTP ingestion endpoint, exhausting the process memory and causing a denial of service.

Affected Systems

The flaw affects Elastic Filebeat installations. No specific version range is listed in the advisory, but the discussion link references versions 8.19.18 and 9.3.1, suggesting that earlier releases are vulnerable. All systems running Filebeat that expose the HTTP ingestion interface to external traffic are at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while no EPSS value is available so the exploitation probability is unclear. Because the incident is not listed in CISA KEV, it is not known to be actively exploited in the wild. The attack vector appears to be remote: any host able to reach the ingestion endpoint over HTTP can trigger the resource exhaustion; therefore securing the endpoint and applying the vendor fix are essential.

Generated by OpenCVE AI on September 3, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Filebeat to the latest available version (e.g., 8.19.18 or newer) to address the denial‑of‑service issue
  • Configure firewall or network policies to restrict access to the HTTP ingestion endpoint to trusted hosts only
  • Monitor memory usage and service responsiveness for signs of abnormal resource consumption

Generated by OpenCVE AI on September 3, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:filebeat:*:*:*:*:*:*:*:*

Thu, 03 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic filebeat
Vendors & Products Elastic
Elastic filebeat

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.
Title Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Elastic Filebeat
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:11.035Z

Reserved: 2026-08-24T21:13:45.972Z

Link: CVE-2026-78588

cve-icon Vulnrichment

Updated: 2026-09-02T15:49:54.054Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:40.307

Modified: 2026-09-03T19:12:32.430

Link: CVE-2026-78588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:45:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling