CVE-2026-72674
EUVD-2026-5826113.08.2026, 20:17
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor de-duplicated before it was used to assemble the response for each matching document. A single crafted request could therefore make Kibana build a response far larger than the data it was derived from, and the resulting processing and memory pressure exhausts the resources of the Kibana instance.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 9.3.0 ≤ 𝑥 < 9.3.8 |
| elastic | kibana | 9.4.0 ≤ 𝑥 < 9.4.4 |
𝑥
= Vulnerable software versions