Description
Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal series data properties with an excessively large quantity value.
Problem types
CWE-1284 Improper Validation of Specified Quantity in Input
Product status
9.3.0 (semver)
9.0.0 (semver)
8.0.0 (semver)
References
discuss.elastic.co/...3-2-security-update-esa-2026-20/385535