Allocation of Resources Without Limits or Throttling in Kibana - CVE-2026-42397
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Entity Analytics endpoints when handling specially crafted requests containing oversized input values. A remote user can submit a specially crafted request containing an oversized input value to cause a denial of service.
Only deployments that use the affected Entity Analytics functionality are vulnerable.