{"id":"CVE-2026-26931","title":"Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).","summary":"Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).","severity":"medium","cvss":5.7,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-789"],"vendor":"elastic","product":"metricbeat","affected":["metricbeat >= 8.0.0, < 8.19.13","metricbeat >= 9.0.0, < 9.2.5"],"patched":["metricbeat 9.2.5"],"published":"2026-03-19","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-26931","references":[{"url":"https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532","label":"security@elastic.co"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26931"},{"url":"https://github.com/elastic/beats/commit/de072c4e371eafeb2a42d65b9ad513f666e4ffd7"},{"url":"https://github.com/elastic/beats"}],"tags":["nvd","osv","go"],"epss":0.00183,"epssPercentile":0.08161,"ingestedAt":"2026-09-04T14:22:25.440Z","aliases":["GHSA-5vrw-qjxw-89r5","GO-2026-4790"],"ecosystem":"go","slug":"CVE-2026-26931","body":"## Overview\n\nMemory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).\n\n## Affected\n\n- `metricbeat >= 8.0.0, < 8.19.13`\n- `metricbeat >= 9.0.0, < 9.2.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `metricbeat 9.2.5`\n\n## Package advisory (CVE-2026-26931)\n\nAffected packages:\n\n- `github.com/elastic/beats/v7 < 7.0.0-alpha2.0.20260112100137-de072c4e371e`\n\nPatched in:\n\n- `github.com/elastic/beats/v7 7.0.0-alpha2.0.20260112100137-de072c4e371e`\n\nSource: https://osv.dev/vulnerability/GHSA-5vrw-qjxw-89r5","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}