← volver
CVE-2026-42399

Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

CVSS 6.5 MEDIUMEPSS 0.3%CWE-400
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
28 may 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression containing deeply chained function calls. The resulting data structure grows without bound, exhausting available memory and causing the Kibana service to crash and become unavailable to all users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Productos afectados
Elastic · Kibana

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →