Resource exhaustion in Kibana - CVE-2026-63260
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Kibana when processing a specially crafted oversized request payload. A remote user can send a specially crafted oversized request payload to cause a denial of service.
The issue can exhaust available heap memory in the Kibana process and cause the service to crash.