GHSA-27qj-9gvp-8rh9

Suggest an improvement
Source
https://github.com/advisories/GHSA-27qj-9gvp-8rh9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-27qj-9gvp-8rh9/GHSA-27qj-9gvp-8rh9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-27qj-9gvp-8rh9
Aliases
Downstream
CGA (196)
MINI (10)
Published
2026-03-19T18:31:19Z
Modified
2026-09-10T03:50:36Z
Severity
  • 5.7 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Packetbeat does not properly validate an array index in multiple protocol parser components
Details

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface can trigger out-of-bounds read operations, resulting in application crashes or resource exhaustion. This requires the attacker to be positioned on the same network segment as the Packetbeat deployment or to control traffic routed to monitored interfaces.

Database specific
{
    "cwe_ids":  [
        "CWE-129"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-19T21:23:15Z",
    "nvd_published_at":  "2026-03-19T18:16:21Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/elastic/beats/v7

Package

Name
github.com/elastic/beats/v7
View open source insights on deps.dev
Purl
pkg:golang/github.com/elastic/beats/v7

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.0.0-alpha2.0.20260126223743-dec1b31111ec

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-27qj-9gvp-8rh9/GHSA-27qj-9gvp-8rh9.json"