Allocation of Resources Without Limits or Throttling in Filebeat - CVE-2026-78588
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the Filebeat HTTP ingestion endpoint when handling specially crafted compressed requests. A remote user can send specially crafted compressed requests to cause a denial of service.
Only deployments where the HTTP endpoint input has been explicitly enabled are affected. This input is disabled by default.