Skip to main content

Vendor/product archive

elasticsearch / packetbeat CVEs

Beta · best-effort

6 CVEs tagged to elasticsearch / packetbeat0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-26933

Published Mar 19, 2026

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker w…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26932

Published Feb 26, 2026

Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can se…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68388

Published Dec 18, 2025

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68382

Published Dec 18, 2025

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68381

Published Dec 18, 2025

Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause sign…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11480

Published Dec 8, 2017

Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is abl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1