Vector: Unauthenticated denial of service in the `logstash` source via nested compressed frames (stack exhaustion and decompression amplification).
Published Sep 22, 2026
8.7
HIGHCVSS 4.0
EPSS 0.52%
Description
Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send many nested compressed frames, causing recursive decoding that exhausts the worker thread stack and aborts the process. The same nested construction amplifies decompressed input, and process termination can halt log ingestion for every tenant on a shared pipeline. This issue is fixed in version 0.57.0.
Affected products
-
- Version >= 0.15.0, < 0.57.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vectordotdev | Vector | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://github.com/vectordotdev/vector/commit/57fed991083c9a43d5fda2d5b3bf4718aedf6526 x_refsource_MISC
- https://github.com/vectordotdev/vector/pull/25825 x_refsource_MISC
- https://github.com/vectordotdev/vector/releases/tag/v0.57.0 x_refsource_MISC
- https://github.com/vectordotdev/vector/security/advisories/GHSA-qp6f-fpfx-4gg6 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/vectordotdev/vector/commit/57fed991083c9a43d5fda2d5b3bf4718aedf6526 | x_refsource_MISC | |
| https://github.com/vectordotdev/vector/pull/25825 | x_refsource_MISC | |
| https://github.com/vectordotdev/vector/releases/tag/v0.57.0 | x_refsource_MISC | |
| https://github.com/vectordotdev/vector/security/advisories/GHSA-qp6f-fpfx-4gg6 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.