Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcw2-vpp7-52v9

Опубликовано: 28 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression containing deeply chained function calls. The resulting data structure grows without bound, exhausting available memory and causing the Kibana service to crash and become unavailable to all users.

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression containing deeply chained function calls. The resulting data structure grows without bound, exhausting available memory and causing the Kibana service to crash and become unavailable to all users.

EPSS

Процентиль: 22%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion visualization expression containing deeply chained function calls. The resulting data structure grows without bound, exhausting available memory and causing the Kibana service to crash and become unavailable to all users.

CVSS3: 6.5
debian
3 месяца назад

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to deni ...

EPSS

Процентиль: 22%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400