Buffer overflow in Filebeat and Filebeat OSS - CVE-2025-68383
Published: December 19, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error within the Filebeat Syslog parser and the Libbeat Dissect processor. A remote attacker can pass specially crafted input to the system that will be logged in a Syslog message or use a malicious tokenizer pattern in the Dissect configuration to trigger buffer overflow and perform a denial of service attack.
Affected software
Filebeat OSS
How to mitigate CVE-2025-68383
Filebeat OSS - addressed in versions 8.19.9, 9.1.9, 9.2.3