CVE-2026-26931Medium· 5.7▾ SunlitMemory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
metricbeat >= 8.0.0, < 8.19.13metricbeat >= 9.0.0, < 9.2.5Upgrade past the affected range:
metricbeat 9.2.5Affected packages:
github.com/elastic/beats/v7 < 7.0.0-alpha2.0.20260112100137-de072c4e371ePatched in:
github.com/elastic/beats/v7 7.0.0-alpha2.0.20260112100137-de072c4e371eConnected by shared product, vendor, weakness, or advisory.
CVE-2026-26933Medium· 5.7Packetbeat does not properly validate an array index in multiple protocol parser components
CVE-2025-68383Medium· 6.5Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
CVE-2026-72656Medium· 6.5Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)
CVE-2024-37286Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2024-23448Medium· 5.7APM Server vulnerable to Insertion of Sensitive Information into Log File
CVE-2026-77322High· 7.5SIPGO is a library for writing SIP services in the GO language