Denial of Service Vulnerability in Wazuh Authentication Middleware
CVE-2026-25771
What is CVE-2026-25771?
A Denial of Service vulnerability was identified in the Wazuh API, affecting versions 4.3.0 to 4.14.3. The issue arises due to the API's authentication middleware, which improperly handles asynchronous calls, allowing unauthenticated attackers to exploit the system. By sending a high volume of requests with invalid Bearer tokens, an attacker can overload the synchronous function responsible for disk I/O operations. This leads to significant delays in processing legitimate requests and ultimately may render the application incapable of functioning as intended. The vulnerability has been addressed in version 4.14.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wazuh >= 4.3.0, < 4.14.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
