PT-2026-79946 · Bitnami · Kibana
Published
2026-08-19
·
Updated
2026-08-19
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the evaluation runs synchronously, a single request consumes the Kibana request-processing thread indefinitely, and Kibana stops responding to all further requests until the service is restarted.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kibana