MEDIUM6.5
GHSA-w2gr-585j-r428
Metricbeat affected by multiple denial of service vulnerabilities
Quick fix
GHSA-w2gr-585j-r428 — github.com/elastic/beats/v7: upgrade to the fixed version with the command below.
go get github.com/elastic/beats/v7@v7.0.0-alpha2.0.20251217054608-6e42552a23ceDetails
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/elastic/beats/v7
Introduced in:
0Fixed in: 7.0.0-alpha2.0.20251217054608-6e42552a23ceFix
go get github.com/elastic/beats/v7@v7.0.0-alpha2.0.20251217054608-6e42552a23ceGo/github.com/elastic/beats/v7
Introduced in:
8.0.0Fixed in: 8.19.10Fix
go get github.com/elastic/beats/v7@v8.19.10Go/github.com/elastic/beats/v7
Introduced in:
9.0.0Fixed in: 9.1.10Fix
go get github.com/elastic/beats/v7@v9.1.10Go/github.com/elastic/beats/v7
Introduced in:
9.2.0Fixed in: 9.2.4Fix
go get github.com/elastic/beats/v7@v9.2.4References
- https://nvd.nist.gov/vuln/detail/CVE-2026-0528[ADVISORY]
- https://github.com/elastic/beats/commit/0025fbfe668936eb8fa65b838508faf3c3c04387[WEB]
- https://github.com/elastic/beats/commit/6e42552a23cec734e7977ebd3eb7fb797ddce456[WEB]
- https://github.com/elastic/beats/commit/c7664c91a5a68c2df782bfeffe4fb7f42ff2ad1a[WEB]
- https://discuss.elastic.co/t/metricbeat-8-19-10-9-1-10-9-2-4-security-update-esa-2026-01/384519[WEB]
- https://github.com/elastic/beats[PACKAGE]