CVE-2025-68388
18.12.2025, 22:16
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.Enginsight
| Vendor | Product | Version |
|---|---|---|
| elasticsearch | packetbeat | 8.6.0 ≤ 𝑥 < 8.19.9 |
| elasticsearch | packetbeat | 9.0.0 ≤ 𝑥 < 9.1.9 |
| elasticsearch | packetbeat | 9.2.0 ≤ 𝑥 < 9.2.3 |
𝑥
= Vulnerable software versions