PT-2026-79946 · Bitnami · Kibana

Published

2026-08-19

·

Updated

2026-08-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the evaluation runs synchronously, a single request consumes the Kibana request-processing thread indefinitely, and Kibana stops responding to all further requests until the service is restarted.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-KIBANA-2026-72663

Affected Products

Kibana