以下是对该漏洞描述的专业翻译: APM 服务器中针对高度压缩数据的不当处理(CWE-409)可能导致通过“过度内存分配”(CAPEC-130)引发持续性拒绝服务(DoS)。拥有源码映射(source map)内容写入权限的认证用户,可以存储特制的、高度压缩的内容;当 APM 服务器后续处理该内容时,会耗尽可用内存,从而导致进程终止。由于该存储内容未被移除,此条件将在每次重启时重现,形成持续性故障。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Apm Server | 8.0.0 ~ 8.19.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78604 | 7.8 HIGH | Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Pr |
| CVE-2026-78590 | 7.3 HIGH | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading to Unauthori |
| CVE-2026-78588 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Filebeat Leading to Denial of Serv |
| CVE-2026-78586 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servic |
| CVE-2026-78599 | 6.5 MEDIUM | Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal Resources |
| CVE-2026-78591 | 6.3 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kibana L |
| CVE-2026-78601 | 5.5 MEDIUM | Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index Data Exposure |
| CVE-2026-78598 | 5.4 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposure of Machine |
| CVE-2026-78609 | 5.4 MEDIUM | Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorized Modificatio |
| CVE-2026-78602 | 5.3 MEDIUM | Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps Server Leading |
| CVE-2026-82293 | 4.3 MEDIUM | Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption |
| CVE-2026-78584 | 4.3 MEDIUM | Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure |
| CVE-2026-78600 | 3.5 LOW | Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace |
| CVE-2026-78587 | 3.1 LOW | Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent Upload Opera |
No comments yet