Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vectordotdev
Vectordotdev vector |
|
| Vendors & Products |
Vectordotdev
Vectordotdev vector |
Tue, 22 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a minimal frame declaring a multi-gigabyte payload, causing an excessive allocation that can abort Vector or invoke the host OOM killer. Because the allocation follows the declared length rather than bytes transmitted, the attacker has low resource cost, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0. | |
| Title | Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation. | |
| Weaknesses | CWE-130 CWE-789 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T16:06:54.582Z
Reserved: 2026-08-20T20:52:01.926Z
Link: CVE-2026-77619
Updated: 2026-09-22T16:06:42.744Z
Status : Received
Published: 2026-09-22T16:17:55.333
Modified: 2026-09-22T17:17:25.303
Link: CVE-2026-77619
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:14:16Z