Vulnerability Report: GO-2026-4790
- CVE-2026-26931, GHSA-5vrw-qjxw-89r5
- Affects: github.com/elastic/beats, github.com/elastic/beats/v7
- Published: Apr 07, 2026
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service in github.com/elastic/beats
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-5vrw-qjxw-89r5.
Affected Packages
-
PathGo VersionsSymbols
-
before v7.0.0-alpha2.0.20260112100137-de072c4e371e
-
before v7.0.0-alpha2.0.20260112100137-de072c4e371e
1 unexported affected symbols
- init
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
Aliases
References
- https://github.com/advisories/GHSA-5vrw-qjxw-89r5
- https://github.com/elastic/beats/commit/de072c4e371eafeb2a42d65b9ad513f666e4ffd7
- https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532
- https://vuln.go.dev/ID/GO-2026-4790.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.