Improper handling of highly compressed data in APM Server - CVE-2026-78594

 

Improper handling of highly compressed data in APM Server - CVE-2026-78594

Published: September 2, 2026


Vulnerability identifier: #VU146675
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78594
CWE-ID: CWE-409
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in source map processing in APM Server when processing stored source map content. A remote privileged user can store specially crafted, highly compressed content to cause a denial of service.

The condition recurs on every restart until the stored content is removed. Only instances with real user monitoring enabled and source map fetching configured are vulnerable.


Affected software

APM Server

How to mitigate CVE-2026-78594

Install security update from vendor's website.

APM Server - addressed in versions 8.19.20, 9.4.5, 9.5.1

External References

Related Security Bulletins