Untriaged
Permalink
CVE-2026-26931
5.7 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): ADJACENT_NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
Affected products
Metricbeat
- =<8.19.12
Matching in nixpkgs
pkgs.metricbeat
Lightweight shipper for metrics
Package maintainers
-
@basvandijk Bas van Dijk <v.dijk.bas@gmail.com>
-
@fadenb Tristan Helmich <tristan.helmich+nixos@gmail.com>
-
@dfithian Daniel Fithian <daniel.m.fithian@gmail.com>