Description
Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.
Problem types
CWE-129 Improper Validation of Array Index
Product status
9.0.0 (semver)
8.0.0 (semver)
Credits
giant_anteater
References
discuss.elastic.co/...2-5-security-update-esa-2026-10/385247