Elastic APM Server 8.x < 8.19.20 / 9.0.x < 9.4.5 / 9.5.x < 9.5.1 DoS (ESA-2026-152)

medium Nessus Plugin ID 347966

Synopsis

The Elastic APM Server installation on the remote host is affected by a denial of service vulnerability.

Description

The version of Elastic APM Server installed on the remote host is 8.x prior to 8.19.20, or 9.0.x prior to 9.4.5, or 9.5.x prior to 9.5.1. It is, therefore, affected by a vulnerability as referenced in the ESA-2026-152 advisory.

- Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that exhausts the memory available to APM Server when it is later processed, terminating the process. The condition recurs on every restart until the stored content is removed. (CVE-2026-78594)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Elastic APM Server version 8.19.20, 9.4.5, or 9.5.1 or later as appropriate for your release branch.

See Also

http://www.nessus.org/u?5ae6c387

Plugin Details

Severity: Medium

ID: 347966

File Name: elastic_apm_server_ESA-2026-152.nasl

Version: 1.1

Type: Local

Family: Misc.

Published: 9/18/2026

Updated: 9/18/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.64

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:N/A:C

CVSS Score Source: CVE-2026-78594

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/a:elastic:apm_server

Required KB Items: Settings/ParanoidReport, installed_sw/Elastic APM Server

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 9/1/2026

Reference Information

CVE: CVE-2026-78594