VDB
Sign up
MEDIUM5.7

GHSA-5vrw-qjxw-89r5

Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service

Quick fix

GHSA-5vrw-qjxw-89r5 — github.com/elastic/beats/v7: upgrade to the fixed version with the command below.

go get github.com/elastic/beats/v7@v7.0.0-alpha2.0.20260112100137-de072c4e371e

Details

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/elastic/beats/v7
Introduced in: 0Fixed in: 7.0.0-alpha2.0.20260112100137-de072c4e371e
Fixgo get github.com/elastic/beats/v7@v7.0.0-alpha2.0.20260112100137-de072c4e371e

References