VendorsElasticsearchpacketbeatall versions
Vulnerabilities

Elasticsearch Packetbeat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2017-11480
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat from properly logging other PostgreSQL traffic.
Published 2017-12-08 · Modified
7.5EPSS 0.014
CVE-2026-26932
Improper Validation of Array Index in Packetbeat Leading to Denial of Service
Published 2026-02-26 · Analyzed
7.5EPSS 0.007
CVE-2025-68381
Packetbeat Improper Bounds Check
Published 2025-12-18 · Analyzed
6.5EPSS 0.005
CVE-2025-68382
Packetbeat Out-of-bounds Read
Published 2025-12-18 · Analyzed
6.5EPSS 0.002
CVE-2026-26933
Improper Validation of Array Index in Packetbeat Leading to Denial of Service
Published 2026-03-19 · Analyzed
5.7EPSS 0.003
CVE-2025-68388
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.
Published 2025-12-18 · Analyzed
5.3EPSS 0.004