Memory Allocation Vulnerability in Metricbeat by Elastic
CVE-2026-26931
5.7MEDIUM
What is CVE-2026-26931?
A vulnerability exists within the Metricbeat remote_write HTTP handler due to improper memory allocation that accepts excessively large size values. This flaw can lead to Denial of Service (DoS) conditions by exploiting memory resources through excessive allocation. Attackers could potentially disrupt service availability, thus impacting operations reliant on metric data collection and analysis. Users are advised to apply the latest security updates to mitigate this risk.
Affected Version(s)
Metricbeat 8.0.0 <= 8.19.12