FlawAtlas
Search the atlas
CVE-2026-0528 Moderate

Metricbeat affected by multiple denial of service vulnerabilities in github.com/elastic/beats

Metricbeat affected by multiple denial of service vulnerabilities in github.com/elastic/beats

Exploit probability 0.3%
Published March 10, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

4 explicit affected versions

Go github.com/elastic/beats/v7
Go github.com/elastic/beats
Go github.com/elastic/beats/v7

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-0528

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.

View original source
Open Source Vulnerabilities GHSA-w2gr-585j-r428

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.

View original source
Open Source Vulnerabilities GO-2026-4360

Metricbeat affected by multiple denial of service vulnerabilities in github.com/elastic/beats

View original source

05 / REFERENCES

Further evidence