CVE-2025-68383Medium· 6.5▾ SunlitFilebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.
github.com/elastic/beats/v7 >= 7.7.0, < 8.19.9github.com/elastic/beats/v7 >= 9.0.0, < 9.1.9github.com/elastic/beats/v7 >= 9.2.0, < 9.2.3github.com/elastic/beats/v7 < 7.0.0-alpha2.0.20251204214633-dd3af18220bfgithub.com/elastic/beats <= 7.6.2Upgrade to a patched release:
github.com/elastic/beats/v7 8.19.9github.com/elastic/beats/v7 9.1.9github.com/elastic/beats/v7 9.2.3github.com/elastic/beats/v7 7.0.0-alpha2.0.20251204214633-dd3af18220bfConnected by shared product, vendor, weakness, or advisory.
CVE-2026-26933Medium· 5.7Packetbeat does not properly validate an array index in multiple protocol parser components
CVE-2026-26931Medium· 5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-14047High· 7.2A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users
CVE-2026-78602Medium· 5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126)