CVE-2026-33754: Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser by sending a crafted message header with an arbitrarily large payload length. The length is trusted before authentication/decryption and used directly to allocate memory, allowing unauthenticated denial of service of the cluster service. This issue has been fixed in version 4.14.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wazuh (cluster protocol)to a version that resolves this vulnerability.Fixed in 4.14.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33754?
The severity of CVE-2026-33754 is classified as medium with a score of 6.5.
How do I fix CVE-2026-33754?
To fix CVE-2026-33754, upgrade Wazuh to version 4.14.5 or later.
What impact does CVE-2026-33754 have on Wazuh?
CVE-2026-33754 allows a remote attacker to trigger memory exhaustion, leading to a denial of service.
Which versions of Wazuh are affected by CVE-2026-33754?
CVE-2026-33754 affects Wazuh versions from 3.9.0 to prior to 4.14.5.
Is CVE-2026-33754 an authenticated vulnerability?
CVE-2026-33754 is an unauthenticated vulnerability that can be exploited without user credentials.