Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0530

Опубликовано: 13 янв. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

A flaw was found in Kibana Fleet. A remote attacker could exploit this vulnerability by sending a specially crafted request, leading to an excessive allocation of resources. This continuous consumption of system resources can result in service degradation or complete unavailability, effectively causing a Denial of Service (DoS).

Отчет

This issue allows a remote attacker with low-level privileges to cause an excessive allocation of resources by sending specially crafted requests, eventually resulting in a denial of service. As the attacker must have low-level privileges to exploit this issue, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2429391kibana: allocation of resources without limits or throttling via specially crafted request

EPSS

Процентиль: 19%
0.00059
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

CVSS3: 6.5
debian
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...

CVSS3: 6.5
github
3 месяца назад

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

EPSS

Процентиль: 19%
0.00059
Низкий

6.5 Medium

CVSS3