Memory Allocation Issue in Wazuh Open-Source Security Platform
CVE-2026-71540
7.5HIGH
What is CVE-2026-71540?
A memory allocation vulnerability exists in the Wazuh security platform affecting versions 3.9.0 to 4.14.7. The issue arises in the wazuh-clusterd component, where an unauthenticated network peer can define a payload buffer size using a 20-byte cluster protocol header. This allows malicious actors to allocate large memory segments of up to 256 MiB without proper validation, leading to potential memory exhaustion. The cluster listener fails to impose limitations on concurrent connections, which can escalate memory consumption and ultimately disrupt the cluster process, impacting synchronization and distributed API services. The vulnerability has been addressed in version 4.14.7.
Affected Version(s)
wazuh >= 3.9.0, < 4.14.7
