CVE-2026-103005

Summary

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large description field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.

Affected Software

VendorProductVersion RangeStatus
ElasticElasticsearch8.12.0 <= 8.19.22affected
ElasticElasticsearch9.0.0 <= 9.3.8affected
ElasticElasticsearch9.4.0 <= 9.4.7affected
ElasticElasticsearch9.5.0 <= 9.5.4affected

Weaknesses

  • CWE-789: CWE-789 Memory Allocation with Excessive Size Value

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References