CVE-2026-61811: Wazuh
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a depth limit while allocating two large local buffers in each stack frame. An enrolled agent can submit a Windows EventChannel event containing an element with enough attributes to exhaust the analysisd worker-thread stack, trigger a segmentation fault, and interrupt log ingestion. The element-depth limit in _ReadElem() does not constrain the number of attributes on one element, so it does not prevent this condition. This issue is fixed in version 4.14.7.
Affected products
- Wazuh Wazuh: from 3.8.0, before 4.14.7 (fixed in 4.14.7)
Published 2026-09-24. Last modified 2026-09-30.