Impact
Filebeat has a resource allocation flaw that allows an attacker to send numerous specially crafted compressed requests to its HTTP ingestion endpoint, exhausting the process memory and causing a denial of service.
Affected Systems
The flaw affects Elastic Filebeat installations. No specific version range is listed in the advisory, but the discussion link references versions 8.19.18 and 9.3.1, suggesting that earlier releases are vulnerable. All systems running Filebeat that expose the HTTP ingestion interface to external traffic are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while no EPSS value is available so the exploitation probability is unclear. Because the incident is not listed in CISA KEV, it is not known to be actively exploited in the wild. The attack vector appears to be remote: any host able to reach the ingestion endpoint over HTTP can trigger the resource exhaustion; therefore securing the endpoint and applying the vendor fix are essential.
OpenCVE Enrichment