Vulnerability Description
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elasticsearch | Packetbeat | >= 8.6.0, < 8.19.9 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-68388?
CVE-2025-68388 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IP...
How severe is CVE-2025-68388?
CVE-2025-68388 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-68388?
Check the references section above for vendor advisories and patch information. Affected products include: Elasticsearch Packetbeat.