Junglewise Threat Intelligence

CVE-2025-68388: GO-2025-4253 - Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments in github.com/elastic/beats

CVE-2025-68388 · Severity: low · CVSS 3.1 · Published 2026-01-23

Technologies: github.com/elastic/beats (Go), github.com/elastic/beats/v7 (Go). Vendors: Go.

Executive brief

Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments in github.com/elastic/beats

Affected products

  • Go github.com/elastic/beats
  • Go github.com/elastic/beats/v7

Related threats