Filebeat 8.19.18, 9.3.1 Security Update (ESA-2026-165)

Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the memory resources of the Filebeat process.

Affected Versions:

  • 8.x: All versions from 8.0.0 up to and including 8.19.17
  • 9.x: All versions from 9.0.0 up to and including 9.3.0

Affected Configurations:

Only Filebeat deployments where the HTTP endpoint input has been explicitly enabled are affected. This input is disabled by default. Deployments that have not enabled this input are not affected.

Solutions and Mitigations:

The issue is resolved in Filebeat versions 8.19.18 and 9.3.1.

For Users that Cannot Upgrade:

Users who cannot immediately upgrade should disable the HTTP endpoint input if it is not operationally required.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-78588
Problem Type: CWE-770 - Allocation of Resources Without Limits or Throttling
Impact: CAPEC-130 - Excessive Allocation

Acknowledgements: Elastic would like to thank Pavel Kohout of Aisle Research (Aisle.com) for reporting this vulnerability.