CVE-2026-78594

Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:apm_server:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:apm_server:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:apm_server:9.5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 19:13


NVD link : CVE-2026-78594

Mitre link : CVE-2026-78594

CVE.ORG link : CVE-2026-78594


JSON object : View

Products Affected

elastic

  • apm_server
CWE
CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)