CVE-2026-78594
Received Received - Intake

Improper Handling of Compressed Data in APM Server

Vulnerability report for CVE-2026-78594, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Elastic

Description

Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
elastic apm_server *
elastic apm_server to 8.19.20 (exc)
elastic apm_server to 9.4.5 (exc)
elastic apm_server to 9.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper handling of highly compressed data in APM Server, leading to a persistent denial of service. An authenticated user with write access can store specially crafted, highly compressed content that exhausts APM Server's memory when processed, causing the server to terminate. The issue recurs on every restart until the malicious content is removed.

Detection Guidance

Check APM Server version using 'apm-server version' command. If using versions 8.19.19 or below (8.x) or 9.4.4 or below (9.x), including 9.5.0, the system is vulnerable. Verify if Real User Monitoring (RUM) is enabled and source map fetching is configured.

Impact Analysis

This vulnerability can cause APM Server to crash repeatedly, disrupting monitoring and logging services. It requires an authenticated user with write access and specific configurations like RUM enabled and source map fetching configured. The impact is limited to affected deployments and persists until the malicious content is manually removed or mitigations are applied.

Mitigation Strategies

Upgrade APM Server to versions 8.19.20, 9.4.5, or 9.5.1. If upgrading is not possible, disable source map processing or disable RUM entirely to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78594. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart