Improper handling of highly compressed data in Kibana - CVE-2026-72628
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in Streams content pack processing when processing specially crafted compressed content. A remote user can supply specially crafted content to cause a denial of service.
Only deployments with Streams enabled and the Streams content packs capability turned on are vulnerable, and neither is enabled in a default installation.