Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed. | |
| Title | Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-09-02T15:58:12.264Z
Reserved: 2026-08-24T21:13:51.299Z
Link: CVE-2026-78594
Updated: 2026-09-02T15:50:54.060Z
Status : Received
Published: 2026-09-02T15:17:40.700
Modified: 2026-09-02T16:17:24.780
Link: CVE-2026-78594
No data.
OpenCVE Enrichment
No data.
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)