Github.Com Elastic Beats V7 vulnerabilities
6 known vulnerabilities affecting github.com/elastic_beats_v7.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2026-26931MEDIUM≥ 0, < 7.0.0-alpha2.0.20260112100137-de072c4e371e2026-03-19
CVE-2026-26931 [MEDIUM] CWE-789 Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).
ghsaosv
CVE-2026-26933MEDIUM≥ 0, < 7.0.0-alpha2.0.20260126223743-dec1b31111ec2026-03-19
CVE-2026-26933 [MEDIUM] CWE-129 Packetbeat does not properly validate an array index in multiple protocol parser components
Packetbeat does not properly validate an array index in multiple protocol parser components
Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface ca
ghsaosv
CVE-2026-0528MEDIUM≥ 0, < 7.0.0-alpha2.0.20251217054608-6e42552a23ce≥ 8.0.0, < 8.19.10+2 more2026-01-13
CVE-2026-0528 [MEDIUM] CWE-129 Metricbeat affected by multiple denial of service vulnerabilities
Metricbeat affected by multiple denial of service vulnerabilities
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the P
ghsaosv
CVE-2025-68388HIGH≥ 0, < 7.0.0-alpha2.0.20251209162832-28cfc80d2f4e2025-12-19
CVE-2025-68388 [HIGH] CWE-770 Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to denial-of-service in Packetbeat.
ghsaosv
CVE-2025-68383MEDIUM≥ 7.7.0, < 8.19.9≥ 9.0.0, < 9.1.9+2 more2025-12-19
CVE-2025-68383 [MEDIUM] CWE-120 Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service
ghsaosv
CVE-2023-49922MEDIUM≥ 7.0.0, < 7.17.162023-12-12
CVE-2023-49922 [MEDIUM] CWE-532 Elastic Beats inserts sensitive information into log file
Elastic Beats inserts sensitive information into log file
An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or Elastic Agent attempted to ingest, this could lead to the insertion of
ghsaosv