Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61811— Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Worker Thread Stack Exhaustion

Quick assessment

Affected
wazuh wazuh
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Wazuh 是一个开源的安全平台,为端点和云工作负载提供统一的 XDR 和 SIEM 保护功能。从版本 3.8.0 到 4.14.7, 中的 函数在处理 XML 属性时没有设置递归深度限制,且每个栈帧中都会分配两个较大的局部缓冲区。已注册的 Wazuh 代理可以提交一个 Windows EventChannel 事件,其中包含一个拥有足够多属性的元素,从而耗尽 工作线程的栈空间,引发段错误(segmentation fault),并中断日志的接收过程。 中设置的元素深度限制无法约束单个元素上的属性数量,因此无法防止

CVSS 6.5 · Medium EPSS 0.37% · P28
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61811

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Worker Thread Stack Exhaustion
Source: CVE Program / CVE List V5
Vulnerability Description
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a depth limit while allocating two large local buffers in each stack frame. An enrolled agent can submit a Windows EventChannel event containing an element with enough attributes to exhaust the analysisd worker-thread stack, trigger a segmentation fault, and interrupt log ingestion. The element-depth limit in _ReadElem() does not constrain the number of attributes on one element, so it does not prevent this condition. This issue is fixed in version 4.14.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wazuh wazuh >= 3.8.0, < 4.14.7 -

II. Public POCs for CVE-2026-61811

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61811

请登录查看更多情报信息。

Other References for CVE-2026-61811 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61811

No comments yet


Leave a comment