CVE-2026-71540
7.5 HIGHpublic exploit availablePublished 2026-09-24 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size declared in a 20-byte cluster protocol header before Fernet decryption validates the peer. An unauthenticated network peer can declare a payload of up to 256 MiB, stop sending after the header, and retain that allocation until the TCP connection closes. The cluster listener has no application-level per-source connection budget in affected versions, allowing concurrent sockets to multiply memory consumption and potentially terminate the cluster process, disrupt synchronization, and interrupt distributed API forwarding. This issue is fixed in version 4.14.7.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-770
Public exploit & PoC references
- https://github.com/wazuh/wazuh/commit/9a996bc23d28725f6c1f8f7808355d90e20d3382
- https://github.com/wazuh/wazuh/pull/37280
- https://github.com/wazuh/wazuh/releases/tag/v4.14.7
- https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f
- https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f
All references
- https://github.com/wazuh/wazuh/commit/9a996bc23d28725f6c1f8f7808355d90e20d3382
- https://github.com/wazuh/wazuh/pull/37280
- https://github.com/wazuh/wazuh/releases/tag/v4.14.7
- https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f
- https://github.com/wazuh/wazuh/security/advisories/GHSA-78wx-4r6w-w73f
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-12767
- MEDIUMCVE-2026-100600PoC
- LOWCVE-2026-100649PoC
- HIGHCVE-2026-100660PoC
- MEDIUMCVE-2026-100795
- MEDIUMCVE-2026-100812
- MEDIUMCVE-2026-100826
- LOWCVE-2026-101333
Related by shared AI tags and CWE weakness class. Browse the full archive.