SB2026090231 - Improper handling of highly compressed data in APM Server



SB2026090231 - Improper handling of highly compressed data in APM Server

Published: September 2, 2026

Security Bulletin ID SB2026090231
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper handling of highly compressed data (CVE-ID: CVE-2026-78594)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in source map processing in APM Server when processing stored source map content. A remote privileged user can store specially crafted, highly compressed content to cause a denial of service.

The condition recurs on every restart until the stored content is removed. Only instances with real user monitoring enabled and source map fetching configured are vulnerable.


Remediation

Install update from vendor's website.