CVE-2026-61811
6.5 MEDIUMpublic exploit availablePublished 2026-09-24 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a depth limit while allocating two large local buffers in each stack frame. An enrolled agent can submit a Windows EventChannel event containing an element with enough attributes to exhaust the analysisd worker-thread stack, trigger a segmentation fault, and interrupt log ingestion. The element-depth limit in _ReadElem() does not constrain the number of attributes on one element, so it does not prevent this condition. This issue is fixed in version 4.14.7.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-674
Public exploit & PoC references
- https://github.com/wazuh/wazuh/commit/2ac70941c5980a5dd24ad8a0f2be559f840e6a67
- https://github.com/wazuh/wazuh/pull/37147
- https://github.com/wazuh/wazuh/releases/tag/v4.14.7
- https://github.com/wazuh/wazuh/security/advisories/GHSA-9wv5-7qwx-m9w5
- https://github.com/wazuh/wazuh/security/advisories/GHSA-9wv5-7qwx-m9w5
All references
- https://github.com/wazuh/wazuh/commit/2ac70941c5980a5dd24ad8a0f2be559f840e6a67
- https://github.com/wazuh/wazuh/pull/37147
- https://github.com/wazuh/wazuh/releases/tag/v4.14.7
- https://github.com/wazuh/wazuh/security/advisories/GHSA-9wv5-7qwx-m9w5
- https://github.com/wazuh/wazuh/security/advisories/GHSA-9wv5-7qwx-m9w5
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100702PoC
- MEDIUMCVE-2026-102265PoC
- HIGHCVE-2026-102276PoC
- HIGHCVE-2026-102278PoC
- HIGHCVE-2026-102281PoC
- HIGHCVE-2026-102495
- HIGHCVE-2026-102496
- HIGHCVE-2026-102497
Related by shared AI tags and CWE weakness class. Browse the full archive.