Description
Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Published: 2026-09-02
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Incorrect handling of highly compressed data within Elastic APM Server can trigger a persistent denial of service through excessive memory allocation. An authenticated user with write access to source map content may chain specially crafted, highly compressed data that forces the server to exhaust its available memory during later processing, causing the process to terminate. Once the server restarts, the issue recurs until the problematic content is removed. The flaw is classified as CWE‑409 and aligned with CAPEC‑130.

Affected Systems

Elastic APM Server product versions are impacted whenever the described logic flaw exists; the CVE description does not enumerate specific releases, so any APM Server deployment susceptible to this handling bug is affected.

Risk and Exploitability

The CVSS score of 4.9 indicates low to moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can write source map content, a privilege typically held by developers or administrators. Because the denial of service persists across server restarts, successful exploitation can disrupt service availability for an extended period.

Generated by OpenCVE AI on September 3, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Elastic APM Server to the latest version that includes the fix for the high‑compression handling bug.
  • If an update cannot be applied immediately, restrict or revoke write access to source map content for authenticated users.
  • Delete or remove any excessively compressed data stored in source map content from the APM Server repository.

Generated by OpenCVE AI on September 3, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:apm_server:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:apm_server:9.5.0:*:*:*:*:*:*:*

Thu, 03 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic apm Server
Vendors & Products Elastic
Elastic apm Server

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Title Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Elastic Apm Server
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-02T15:58:12.264Z

Reserved: 2026-08-24T21:13:51.299Z

Link: CVE-2026-78594

cve-icon Vulnrichment

Updated: 2026-09-02T15:50:54.060Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T15:17:40.700

Modified: 2026-09-03T19:13:49.230

Link: CVE-2026-78594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:00:04Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)