Remote Denial of Service in Wazuh's Cluster Protocol Parser
CVE-2026-33754

6.5MEDIUM

Key Information:

Vendor

Wazuh

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-33754?

Wazuh, a widely-used open-source platform for threat detection and response, is susceptible to a remote denial of service (DoS) attack. In versions ranging from 3.9.0 to 4.14.4, an attacker can exploit this vulnerability by sending a specially crafted message header that includes an excessively large payload length. This payload length is processed without proper authentication or decryption, leading to potential memory exhaustion in the cluster protocol parser. Consequently, this can cause the cluster service to become unresponsive. The issue has been addressed in version 4.14.5.

Affected Version(s)

wazuh >= 3.9.0, < 4.14.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.