CVE-2026-33464

Source
https://cve.org/CVERecord?id=CVE-2026-33464
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33464.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33464
Aliases
Downstream
Published
2026-05-28T19:35:31.655Z
Modified
2026-07-22T03:08:56.538135Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Uncontrolled Resource Consumption in Kibana Leading to Denial of Service
Details

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially crafted, oversized payload to an internal Kibana API, causing the Kibana process to exhaust available resources and become unresponsive to all users until the service recovers or is restarted.

Database specific
{
    "cna_assigner": "elastic",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33464.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "9.4.0"
                },
                {
                    "last_affected": "9.4.0"
                },
                {
                    "introduced": "9.0.0"
                },
                {
                    "last_affected": "9.3.4"
                },
                {
                    "introduced": "8.0.0"
                },
                {
                    "last_affected": "8.19.15"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-400"
    ]
}
References

Affected packages

Git / github.com/elastic/elasticsearch

Affected ranges

Type
GIT
Repo
https://github.com/elastic/elasticsearch
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:9.4.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.19.16"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.3.5"
        },
        {
            "introduced": "9.4.0"
        },
        {
            "last_affected": "9.4.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

9.*
9.4.0
v9.*
v9.4.0

Database specific

vanir_signatures_modified
"2026-07-22T03:08:56Z"
vanir_signatures
[
    {
        "target": {
            "file": "modules/apm/src/test/java/org/elasticsearch/telemetry/apm/RecordingOtelMeter.java"
        },
        "id": "CVE-2026-33464-a85b3975",
        "digest": {
            "line_hashes": [
                "23074235914325468324376590861514089586",
                "98430579598318027407692933948030043385",
                "187050963769246900287150112416544450660",
                "214623411764654173647043302652335395077",
                "176453353204044914242382593509038157485",
                "213515830173899733296977817562856718047"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/elastic/elasticsearch/commit/0ecfe314ed6ddebb736091bf37b3b6758209b73b"
    },
    {
        "target": {
            "file": "modules/apm/src/test/java/org/elasticsearch/telemetry/apm/RecordingOtelMeter.java"
        },
        "id": "CVE-2026-33464-d726701b",
        "digest": {
            "line_hashes": [
                "23074235914325468324376590861514089586",
                "98430579598318027407692933948030043385",
                "187050963769246900287150112416544450660",
                "214623411764654173647043302652335395077",
                "176453353204044914242382593509038157485",
                "213515830173899733296977817562856718047"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/elastic/elasticsearch/commit/7dcc32bebba091844c0207f9dae8fda6c7d08542"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33464.json"

Git / github.com/elastic/kibana

Affected ranges

Type
GIT
Repo
https://github.com/elastic/kibana
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:kibana:9.4.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.19.16"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.3.5"
        },
        {
            "introduced": "9.4.0"
        },
        {
            "last_affected": "9.4.0"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

9.*
9.4.0
v9.*
v9.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33464.json"