
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78588 is a denial-of-service vulnerability in Elastic Filebeat caused by Allocation of Resources Without Limits or Throttling (CWE-770). An attacker able to reach the Filebeat HTTP ingestion endpoint can send specially crafted compressed requests that exhaust the memory resources of the Filebeat process, rendering it unavailable. The vulnerability affects Filebeat versions 8.0.0 through 8.19.17 and 9.0.0 through 9.3.0. It was published on September 2, 2026, with patches available in versions 8.19.18 and 9.3.1. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Elastic Advisory).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): Filebeat's HTTP ingestion endpoint does not impose adequate limits on the size or number of resources allocated when processing incoming compressed requests. An attacker can exploit this by sending specially crafted, highly compressed payloads (a form of decompression bomb or excessive allocation attack, CAPEC-130) that expand dramatically in memory upon decompression, exhausting the Filebeat process's available memory. Exploitation requires low-level authenticated access to the network-accessible HTTP ingestion endpoint, with no user interaction needed. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Elastic Advisory).
Successful exploitation results in a denial-of-service condition affecting the Filebeat process: memory resources are exhausted, causing the service to crash or become unresponsive. This disrupts log ingestion and forwarding pipelines that depend on Filebeat, potentially causing gaps in security monitoring, log collection, and observability. There is no impact on confidentiality or data integrity, and lateral movement is not directly facilitated by this vulnerability (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of publication. The EPSS score is approximately 0.289% (21st percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-privilege authenticated access to the Filebeat HTTP ingestion endpoint, which limits opportunistic attack surface (GitHub Advisory, Elastic Advisory).
curl or a custom script with appropriate Content-Encoding: gzip or similar headers).dmesg, syslog) indicating OOM (Out of Memory) killer terminating the Filebeat process.filebeat process; high memory consumption by the Filebeat process visible in system monitoring tools (e.g., top, htop, Prometheus metrics).Elastic has released patched versions 8.19.18 and 9.3.1 that address this vulnerability; upgrading to these versions is the recommended remediation (Elastic Advisory). As a workaround, restrict network access to the Filebeat HTTP ingestion endpoint using firewall rules or network access controls to allow only trusted sources. Additionally, consider implementing rate limiting or request size limits at the network or reverse proxy layer to prevent resource exhaustion attacks against the endpoint (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."