Back

MEDIUM

Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)

Published Jul 16, 2026

Description

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger memory exhaustion in the cluster protocol parser by sending a crafted message header with an arbitrarily large payload length. The length is trusted before authentication/decryption and used directly to allocate memory, allowing unauthenticated denial of service of the cluster service. This issue has been fixed in version 4.14.5.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 16, 2026
Updated Jul 17, 2026
Reserved Mar 23, 2026

CISA Vulnrichment

Updated Jul 17, 2026

NVD

Status Analyzed
Modified Jul 20, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 16, 2026
Updated Jul 17, 2026

GitHub

No data