{"schema_version":"1.7.3","id":"GO-2025-4253","published":"2026-01-23T02:28:11Z","modified":"2026-02-04T04:03:03.017114Z","aliases":["CVE-2025-68388","GHSA-fj69-23m4-ccvv"],"related":["CGA-fmhx-hqww-2wxf"],"summary":"Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments in github.com/elastic/beats","details":"Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments in github.com/elastic/beats","affected":[{"package":{"name":"github.com/elastic/beats","ecosystem":"Go","purl":"pkg:golang/github.com/elastic/beats"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"custom_ranges":[{"events":[{"introduced":"8.6.0"},{"fixed":"8.19.9"},{"introduced":"9.0.0"},{"fixed":"9.1.9"},{"introduced":"9.2.0"},{"fixed":"9.2.3"}],"type":"ECOSYSTEM"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4253.json"}},{"package":{"name":"github.com/elastic/beats/v7","ecosystem":"Go","purl":"pkg:golang/github.com/elastic/beats/v7"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.0.0-alpha2.0.20251209162832-28cfc80d2f4e"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/elastic/beats/v7/packetbeat/decoder","symbols":["Decoder.OnPacket","New","fragmentCache.add","fragmentCache.purge"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4253.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fj69-23m4-ccvv"},{"type":"FIX","url":"https://github.com/elastic/beats/commit/28cfc80d2f4e80bfd1c72eb3f849d777751ab870"},{"type":"WEB","url":"https://discuss.elastic.co/t/packetbeat-8-19-9-9-1-9-and-9-2-3-security-update-esa-2025-29/384177"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-4253"}}