Vulnerabilities
Vulnerable Software
Elastic:  >> Apm Server  >> 8.18.3  Security Vulnerabilities
Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed.
CVSS Score
4.9
EPSS Score
0.005
Published
2026-09-02
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
CVSS Score
5.3
EPSS Score
0.004
Published
2023-10-26


Contact Us

Shodan ® - All rights reserved