CVE-2026-0530Allocation of Resources Without Limits or Throttling in Kibana

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 81.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or complete unavailability occurs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDelastic/kibana7.10.07.17.29+3
CVEListV5elastic/kibana7.10.07.17.29+3

🔴Vulnerability Details

2
CVEList
Allocation of Resources Without Limits or Throttling in Kibana Leading to Excessive Allocation2026-01-13
GHSA
GHSA-fwvg-47gh-ppm7: Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted re2026-01-13

📋Vendor Advisories

1
Red Hat
kibana: allocation of resources without limits or throttling via specially crafted request2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2026-0530 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0530 — Elastic Kibana vulnerability | cvebase