CVE-2025-68383
Filebeat vulnerability analysis and mitigation

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.


SourceNVD

Related Filebeat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-41110CRITICAL9.9
  • cAdvisorcAdvisor
  • prometheus-2.51
NoYesJul 24, 2024
CVE-2024-34158HIGH7.5
  • cAdvisorcAdvisor
  • openshift4::ose-cluster-cloud-controller-manager-rhel9-operator@sha256:42b9bd87e28c0ae8ac1dd12de1475c9a81cab0a1279bae9b94c7aa101d2cb2a6_ppc64le
NoYesSep 06, 2024
CVE-2024-34156HIGH7.5
  • cAdvisorcAdvisor
  • openshift4::ose-machine-api-provider-gcp-rhel9@sha256:52dc5b3ed815d78fa1dc1f41608306d9283a6f8fa4f406e8524337983bd0a25b_ppc64le
NoYesSep 06, 2024
CVE-2025-68383MEDIUM6.5
  • FilebeatFilebeat
  • github.com/elastic/beats/v7
NoYesDec 18, 2025
CVE-2024-34155MEDIUM4.3
  • cAdvisorcAdvisor
  • kubernetes-csi-external-resizer-fips-1.8
NoYesSep 06, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management