Denial of Service in Packetbeat Affected by Vulnerable PostgreSQL Protocol Parsing
CVE-2026-26932

5.7MEDIUM

Key Information:

Vendor

Elastic

Vendor
CVE Published:
26 February 2026

What is CVE-2026-26932?

The improper validation of array indices in the PostgreSQL protocol parser of Packetbeat can lead to a Denial of Service (DoS) condition. An attacker can exploit this vulnerability by sending specially crafted packets to the server, which, when the pgsql protocol is enabled, can trigger a Go runtime panic. This event causes the Packetbeat process to crash, interrupting network monitoring capabilities. It's crucial for users to ensure that the PostgreSQL protocol is properly configured and to monitor any updates from Elastic regarding this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Packetbeat 9.0.0 <= 9.2.4

Packetbeat 8.0.0 <= 8.19.10

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

giant_anteater
.