CVE-2025-68388Allocation of Resources Without Limits or Throttling in Elasticsearch Packetbeat

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 67.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateJan 23

Description

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDelasticsearch/packetbeat8.6.08.19.9+2
CVEListV5elastic/packetbeat8.6.08.19.8+2
Gogithub.com/elastic_beats8.6.08.19.9+2
Gogithub.com/elastic_beats_v7< 7.0.0-alpha2.0.20251209162832-28cfc80d2f4e

🔴Vulnerability Details

4
OSV
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments in github.com/elastic/beats2026-01-23
OSV
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments2025-12-19
GHSA
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments2025-12-19
CVEList
CVE-2025-68388: Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of2025-12-18

🕵️Threat Intelligence

1
Wiz
CVE-2025-68388 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-68388 — Elasticsearch Packetbeat vulnerability | cvebase