CVE-2025-68389: Kibana Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and a denial of service (DoS) of the Kibana process via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68389?
CVE-2025-68389 is considered a high-severity vulnerability as it can lead to denial of service (DoS) in Kibana.
How do I fix CVE-2025-68389?
To fix CVE-2025-68389, upgrade Kibana to the latest version where the vulnerability has been patched.
Who is affected by CVE-2025-68389?
Kibana installations, particularly those allowing low-privileged authenticated users, are affected by CVE-2025-68389.
What impact does CVE-2025-68389 have on Kibana?
CVE-2025-68389 allows a user to exhaust computing resources, leading to potential denial of service (DoS) for the Kibana process.
What type of vulnerability is CVE-2025-68389 classified as?
CVE-2025-68389 is classified as an allocation of resources without limits or throttling vulnerability in Kibana.