Beveiligingsadvies

CVE-2026-33754

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-16 23:40:59
Laatst bijgewerkt 2026-07-17 12:16:14
Toegewezen door GitHub_M
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser by sending a crafted message header with an arbitrarily large payload length. The length is trusted before authentication/decryption and used directly to allocate memory, allowing unauthenticated denial of service of the cluster service. This issue has been fixed in version 4.14.5.