CVE-2026-26932
EUVD-2026-886426.02.2026, 18:23
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elasticsearch | packetbeat | 8.0.0 ≤ 𝑥 < 8.19.11 |
| elasticsearch | packetbeat | 9.0.0 ≤ 𝑥 < 9.2.5 |
𝑥
= Vulnerable software versions