PT-2026-98222 · Wazuh · Wazuh

CVE-2026-71540

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 3.9.0 through 4.14.6
Description The wazuh-clusterd component in framework/wazuh/core/cluster/common.py allocates a payload buffer based on the size specified in a 20-byte cluster protocol header before the peer is validated via Fernet decryption. An unauthenticated network peer can specify a payload size up to 256 MiB and cease transmission after the header, maintaining the memory allocation until the TCP connection is closed. Because the cluster listener lacks an application-level per-source connection budget, multiple concurrent sockets can excessively increase memory consumption. This may lead to the termination of the cluster process, disruption of synchronization, and interruption of distributed API forwarding.
Recommendations Update to version 4.14.7.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71540
GHSA-78WX-4R6W-W73F

Affected Products

Wazuh