SB2026090231 - Improper handling of highly compressed data in APM Server
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper handling of highly compressed data (CVE-ID: CVE-2026-78594)
CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in source map processing in APM Server when processing stored source map content. A remote privileged user can store specially crafted, highly compressed content to cause a denial of service.
The condition recurs on every restart until the stored content is removed. Only instances with real user monitoring enabled and source map fetching configured are vulnerable.
Remediation
Install update from vendor's website.