Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39197

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

A flaw was found in Vector. A remote attacker could send a specially crafted compressed request to Vector's HTTP ingest sources, causing unbounded memory allocation during decompression and leading to a Denial of Service (DoS).

Меры по смягчению последствий

Restrict network access to Vector's HTTP and gRPC ingest endpoints using Kubernetes NetworkPolicies to allow connections only from trusted log forwarders. Additionally, configure memory resource limits on Vector pods to prevent a single decompression bomb from exhausting node-level memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2488989vector: Vector: Denial of Service via crafted request to HTTP endpoint

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

CVSS3: 6.5
github
около 2 месяцев назад

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

7.5 High

CVSS3