CVE-2026-26931
MEDIUMMemory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
Title source: cnaDescription
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
Scores
CVSS v3
5.7
EPSS
0.0002
EPSS Percentile
6.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-789
Status
published
Products (2)
elastic/beats
0 - 7.0.0-alpha2.0.20260112100137-de072c4e371eGo
Elastic/Metricbeat
8.0.0 - 8.19.12
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026