Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade the affected package to 4.14.7 or later.
Workaround
No workaround given by the vendor.
Tue, 18 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fernet key can upload a small, highly compressed zip bomb archive that forces wazuh-clusterd on the master node to decompress the full payload into memory, causing memory exhaustion and service disruption. | |
| Title | Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bomb | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T19:27:06.342Z
Reserved: 2026-08-14T14:06:40.513Z
Link: CVE-2026-74046
Updated: 2026-08-18T19:27:03.113Z
Status : Received
Published: 2026-08-18T18:19:34.053
Modified: 2026-08-18T20:17:29.330
Link: CVE-2026-74046
No data.
OpenCVE Enrichment
Updated: 2026-08-18T18:30:16Z