CVE-2026-71540 HIGH
← Quay lại danh sáchinternal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size declared in a 20-byte cluster protocol header before Fernet decryption validates the peer. An unauthenticated network peer can declare a payload of up to 256 MiB, stop sending after the header, and retain that allocation until the TCP connection closes. The cluster listener has no application-level per-source connection budget in affected versions, allowing concurrent sockets to multiply memory consumption and potentially terminate the cluster process, disrupt synchronization, and interrupt distributed API forwarding. This issue is fixed in version 4.14.7.
Chi tiết
| Trạng thái | Received |
| Điểm CVSS | 7.5 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Ngày công bố | 01:18 25/09/2026 |
| Ngày cập nhật | 23:17 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [security-advisories@github.com] https://github.com/wazuh/wazuh/commit/9a996bc23d28725f6c1f8f7808355d90e20d3382
- [security-advisories@github.com] https://github.com/wazuh/wazuh/pull/37280
- [security-advisories@github.com] https://github.com/wazuh/wazuh/releases/tag/v4.14.7
- [security-advisories@github.com] https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 23:17 28/09/2026 | CREATED | cve | HIGH |