CVE-2026-26931: Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remotewrite HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/elastic/beats/v7to a version that resolves this vulnerability.Fixed in 7.0.0-alpha2.0.20260112100137-de072c4e371e
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26931?
CVE-2026-26931 is classified as a Denial of Service vulnerability due to excessive memory allocation.
How do I fix CVE-2026-26931?
To fix CVE-2026-26931, update to the latest version of Elastic Metricbeat that addresses the vulnerability.
What affects CVE-2026-26931?
CVE-2026-26931 affects the Prometheus remote_write HTTP handler in Elastic Metricbeat.
What is the risk of CVE-2026-26931?
The risk of CVE-2026-26931 is that it can lead to service outages due to excessive allocation of memory.
Is CVE-2026-26931 being actively exploited?
As of now, there are no public reports indicating that CVE-2026-26931 is actively exploited in the wild.