APM Server Denial via Highly Compressed Source Map (CWE409/CAPEC130)
CVE-2026-78594 Published on September 2, 2026
Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service
Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
Vulnerability Analysis
CVE-2026-78594 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is a Data Amplification Vulnerability?
The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.
CVE-2026-78594 has been classified to as a Data Amplification vulnerability or weakness.
Products Associated with CVE-2026-78594
Want to know whenever a new CVE is published for Elastic Apm Server? stack.watch will email you.
Affected Versions
Elastic Apm Server:- Version 8.0.0, <= 8.19.19 is affected.
- Version 9.0.0, <= 9.4.4 is affected.
- Version 9.5.0 is affected.