Junglewise Threat Intelligence

CVE-2026-77619: Vector logstash source unbounded memory allocation denial of service

CVE-2026-77619 · Severity: info · Published 2026-09-22

Executive brief

Vector is a high-performance data pipeline for observability and log processing. An unauthenticated remote attacker can connect to Vector's default Logstash listener (port 5044) and send a specially crafted network frame that declares an extremely large payload size without actually sending the data. This causes Vector to allocate excessive memory that can crash the entire service and halt log collection for all users sharing the pipeline.

Technical details

The logstash source in Vector reads a 32-bit compressed-frame length field from network input and allocates a buffer sized to this length without validation or upper bounds. An unauthenticated remote peer can send a minimal frame with a multi-gigabyte declared size to trigger out-of-memory allocation. The vulnerability is a denial-of-service condition through unbounded resource consumption that may invoke the host OOM killer, and affects all Vector instances with the default 0.0.0.0:5044 listener exposed to untrusted networks.

Affected products

  • Vector Vector 0.15.0 to 0.56.x

Timeline

  • 2026-09-22: disclosed
  • 2026-07-13: patched: Fix released in version 0.57.0

References

Related threats