Resource exhaustion in Kibana - CVE-2026-42400
Published: May 29, 2026
Kibana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Kibana request processing when handling a specially crafted compressed request payload prior to authorization checks. A remote user can send a specially crafted compressed request payload to cause a denial of service.
All Kibana configurations accessible to authenticated users are affected.