Vulnerability Report: GO-2026-4789
- CVE-2026-26933, GHSA-27qj-9gvp-8rh9
- Affects: github.com/elastic/beats, github.com/elastic/beats/v7
- Published: Apr 07, 2026
Packetbeat does not properly validate an array index in multiple protocol parser components in github.com/elastic/beats
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-27qj-9gvp-8rh9.
Affected Packages
-
PathGo VersionsSymbols
-
before v7.0.0-alpha2.0.20260126223743-dec1b31111ec
4 unexported affected symbols
- findSocketsOfPid
- hexToIPPort
- hexToIpv6
- parseProcNetProto
-
before v7.0.0-alpha2.0.20260126223743-dec1b31111ec
5 unexported affected symbols
- pgsqlPlugin.parseDataRow
- pgsqlPlugin.parseExtReq
- pgsqlPlugin.parseMessageStart
- readCount
- readLength
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
Aliases
References
- https://github.com/advisories/GHSA-27qj-9gvp-8rh9
- https://github.com/elastic/beats/commit/941098459db6556b837194f40c076b08d51137cb
- https://github.com/elastic/beats/commit/dec1b31111ec3500b82db21ba67dde5c914ee94d
- https://discuss.elastic.co/t/packetbeat-8-19-11-9-2-5-security-update-esa-2026-11/385533
- https://vuln.go.dev/ID/GO-2026-4789.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.