Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted. | |
| Title | Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-01T19:37:26.698Z
Reserved: 2026-08-10T11:17:29.887Z
Link: CVE-2026-72628
Updated: 2026-09-01T19:37:23.729Z
Status : Awaiting Analysis
Published: 2026-09-01T20:17:16.373
Modified: 2026-09-01T21:15:37.123
Link: CVE-2026-72628
No data.
OpenCVE Enrichment
No data.
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)