Improper handling of highly compressed data in APM Server - CVE-2026-78594
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in source map processing in APM Server when processing stored source map content. A remote privileged user can store specially crafted, highly compressed content to cause a denial of service.
The condition recurs on every restart until the stored content is removed. Only instances with real user monitoring enabled and source map fetching configured are vulnerable.