Resource exhaustion in Kibana - CVE-2026-63139
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Kibana Canvas functionality when handling a specially crafted request. A remote user can send a specially crafted request to cause a denial of service.
The issue can cause the Kibana server process to terminate, resulting in a denial of service for all users of the affected instance.