PT-2026-22162 · Elastic · Packetbeat

Giant_Anteater

·

Publicado

2026-02-26

·

Atualizado

2026-03-13

·

CVE-2026-26932

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Packetbeat (affected versions not specified)
Description A flaw exists in the PostgreSQL protocol parser within Packetbeat that allows for Denial of Service through manipulation of input data. Specifically, improper validation of an array index can cause a Go runtime panic, leading to the termination of the Packetbeat process. This requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26932

Produtos afetados

Packetbeat