云虫漏洞情报

CVE-2026-72663 - Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the evaluation runs synchronously, a single request consumes the Kibana request-processing thread indefinitely, and Kibana stops responding to all further requests unti - 漏洞详情

漏洞编号:CVE-2026-72663

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-72663

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-407

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the evaluation runs synchronously, a single request consumes the Kibana request-processing thread indefinitely, and Kibana stops responding to all further requests until the service is restarted.

相关链接

相关漏洞

« 返回首页