CVE-2026-78588
Filebeat vulnerability analysis and mitigation

Overview

CVE-2026-78588 is a denial-of-service vulnerability in Elastic Filebeat caused by Allocation of Resources Without Limits or Throttling (CWE-770). An attacker able to reach the Filebeat HTTP ingestion endpoint can send specially crafted compressed requests that exhaust the memory resources of the Filebeat process, rendering it unavailable. The vulnerability affects Filebeat versions 8.0.0 through 8.19.17 and 9.0.0 through 9.3.0. It was published on September 2, 2026, with patches available in versions 8.19.18 and 9.3.1. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).

Technical details

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): Filebeat's HTTP ingestion endpoint does not impose adequate limits on the size or number of resources allocated when processing incoming compressed requests. An attacker can exploit this by sending specially crafted, highly compressed payloads (a form of decompression bomb or excessive allocation attack, CAPEC-130) that expand dramatically in memory upon decompression, exhausting the Filebeat process's available memory. Exploitation requires low-level authenticated access to the network-accessible HTTP ingestion endpoint, with no user interaction needed. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Elastic Advisory).

Impact

Successful exploitation results in a denial-of-service condition affecting the Filebeat process: memory resources are exhausted, causing the service to crash or become unresponsive. This disrupts log ingestion and forwarding pipelines that depend on Filebeat, potentially causing gaps in security monitoring, log collection, and observability. There is no impact on confidentiality or data integrity, and lateral movement is not directly facilitated by this vulnerability (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of publication. The EPSS score is approximately 0.289% (21st percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-privilege authenticated access to the Filebeat HTTP ingestion endpoint, which limits opportunistic attack surface (GitHub Advisory, Elastic Advisory).

Exploitation steps

  1. Reconnaissance: Identify Filebeat instances with the HTTP ingestion endpoint exposed on the network, using port scanning or service discovery tools targeting default Filebeat HTTP input ports (e.g., 8080 or custom configured ports).
  2. Authentication: Obtain or use low-privilege credentials sufficient to authenticate to the Filebeat HTTP ingestion endpoint, if authentication is enforced.
  3. Craft malicious payload: Prepare a specially crafted compressed HTTP request body (e.g., a decompression bomb) designed to expand to a very large size in memory upon decompression by the Filebeat process.
  4. Send request: Submit the crafted compressed request to the Filebeat HTTP ingestion endpoint (e.g., via curl or a custom script with appropriate Content-Encoding: gzip or similar headers).
  5. Trigger memory exhaustion: Filebeat decompresses the payload without enforcing resource limits, causing memory to be exhausted and the Filebeat process to crash or become unresponsive, resulting in a denial-of-service condition (GitHub Advisory, Elastic Advisory).

Indicators of compromise

  • Network: Unusual or repeated large compressed HTTP POST requests to the Filebeat HTTP ingestion endpoint from unexpected source IPs; abnormally high inbound traffic volume to the Filebeat HTTP input port.
  • Logs: Filebeat process logs showing out-of-memory errors, unexpected crashes, or restarts; OS-level logs (e.g., dmesg, syslog) indicating OOM (Out of Memory) killer terminating the Filebeat process.
  • Process: Sudden termination or repeated restarts of the filebeat process; high memory consumption by the Filebeat process visible in system monitoring tools (e.g., top, htop, Prometheus metrics).
  • File System: Core dump files generated by a crashed Filebeat process in the working directory or configured core dump path.

Mitigation and workarounds

Elastic has released patched versions 8.19.18 and 9.3.1 that address this vulnerability; upgrading to these versions is the recommended remediation (Elastic Advisory). As a workaround, restrict network access to the Filebeat HTTP ingestion endpoint using firewall rules or network access controls to allow only trusted sources. Additionally, consider implementing rate limiting or request size limits at the network or reverse proxy layer to prevent resource exhaustion attacks against the endpoint (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Filebeat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-34158HIGH7.5
  • Go logoGo
  • openshift4::ose-machine-api-provider-azure-rhel9@sha256:14a76ce8135faf5fd84a80b9d82c325bb7678f313de4ef26ed1877c12b073c5b_arm64
NoYesSep 06, 2024
CVE-2024-34156HIGH7.5
  • Go logoGo
  • grafana-10.4
NoYesSep 06, 2024
CVE-2026-78588MEDIUM6.5
  • Filebeat logoFilebeat
  • filebeat-8.19-fips
NoYesSep 02, 2026
CVE-2025-68383MEDIUM6.5
  • Filebeat logoFilebeat
  • metricbeat-9.2
NoYesDec 18, 2025
CVE-2024-34155MEDIUM4.3
  • Go logoGo
  • openshift4::ose-cluster-olm-rhel9-operator@sha256:aca7790786a0c4f3da8672bfb67ca7231a044b669345559c57f699b55b696709_amd64
NoYesSep 06, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management