CVE-2026-63136
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 8.0.0 <= 8.19.14 | affected |
| Elastic | Elasticsearch | 9.3.0 <= 9.3.3 | affected |
| Elastic | Elasticsearch | 9.0.0 <= 9.2.8 | affected |
Weaknesses
- CWE-400: CWE-400 Uncontrolled Resource Consumption
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.