#VU125550 Resource exhaustion in Kibana - CVE-2026-33459
Published: April 9, 2026
Kibana
Elastic Stack
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the automatic import feature when handling specially crafted requests with excessively large input values. A remote user can submit concurrent crafted requests to cause a denial of service.
Only deployments with the automatic import plugin enabled are vulnerable.