Vulnerability Details CVE-2026-78588
Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 21.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-78588
-
cpe:2.3:a:elastic:filebeat:9.0.0
-
cpe:2.3:a:elastic:filebeat:9.0.1
-
cpe:2.3:a:elastic:filebeat:9.0.2
-
cpe:2.3:a:elastic:filebeat:9.0.3
-
cpe:2.3:a:elastic:filebeat:9.0.4
-
cpe:2.3:a:elastic:filebeat:9.0.5
-
cpe:2.3:a:elastic:filebeat:9.0.6
-
cpe:2.3:a:elastic:filebeat:9.0.7
-
cpe:2.3:a:elastic:filebeat:9.0.8
-
cpe:2.3:a:elastic:filebeat:9.1.0
-
cpe:2.3:a:elastic:filebeat:9.1.1
-
cpe:2.3:a:elastic:filebeat:9.1.2
-
cpe:2.3:a:elastic:filebeat:9.1.3
-
cpe:2.3:a:elastic:filebeat:9.1.4
-
cpe:2.3:a:elastic:filebeat:9.1.5
-
cpe:2.3:a:elastic:filebeat:9.1.6
-
cpe:2.3:a:elastic:filebeat:9.1.7
-
cpe:2.3:a:elastic:filebeat:9.1.8
-
cpe:2.3:a:elastic:filebeat:9.1.9
-
cpe:2.3:a:elastic:filebeat:9.2.0
-
cpe:2.3:a:elastic:filebeat:9.2.1
-
cpe:2.3:a:elastic:filebeat:9.2.2
-
cpe:2.3:a:elastic:filebeat:9.2.3