CVE-2026-74039

Source
https://cve.org/CVERecord?id=CVE-2026-74039
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74039.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74039
Aliases
  • GHSA-5vh8-34r8-q74q
Published
2026-08-18T17:26:12.871Z
Modified
2026-08-20T03:48:22.452934227Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context
Details

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allowrunas enabled to exhaust CPU resources by submitting arbitrarily deeply nested JSON structures to the POST /security/user/authenticate/runas endpoint. Attackers can repeatedly submit malformed authcontext bodies with unlimited nesting depth to cause the API framework to consume excessive CPU, denying service to all other API consumers.

Database specific
{
    "cwe_ids": [
        "CWE-1333",
        "CWE-770"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74039.json"
}
References

Affected packages

Git / github.com/wazuh/wazuh

Affected ranges

Type
GIT
Repo
https://github.com/wazuh/wazuh
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.14.7"
        },
        {
            "introduced": "5.0.0-beta2"
        },
        {
            "last_affected": "5.0.0-beta2"
        }
    ]
}

Affected versions

5.*
5.0.0-beta2
v5.*
v5.0.0-beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74039.json"