Impact
Incorrect handling of highly compressed data within Elastic APM Server can trigger a persistent denial of service through excessive memory allocation. An authenticated user with write access to source map content may chain specially crafted, highly compressed data that forces the server to exhaust its available memory during later processing, causing the process to terminate. Once the server restarts, the issue recurs until the problematic content is removed. The flaw is classified as CWE‑409 and aligned with CAPEC‑130.
Affected Systems
Elastic APM Server product versions are impacted whenever the described logic flaw exists; the CVE description does not enumerate specific releases, so any APM Server deployment susceptible to this handling bug is affected.
Risk and Exploitability
The CVSS score of 4.9 indicates low to moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can write source map content, a privilege typically held by developers or administrators. Because the denial of service persists across server restarts, successful exploitation can disrupt service availability for an extended period.
OpenCVE Enrichment