Vulnerabilities (CVE)

Filtered by vendor Elastic Subscribe
Filtered by product Filebeat
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-78588 1 Elastic 1 Filebeat 2026-09-03 N/A 6.5 MEDIUM
Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.
CVE-2025-68383 1 Elastic 1 Filebeat 2026-06-17 N/A 6.5 MEDIUM
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.
CVE-2023-31413 1 Elastic 1 Filebeat 2026-06-17 N/A 3.3 LOW
Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled.