CVE-2026-63140
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 9.0.0 <= 9.3.7 | affected |
| Elastic | Elasticsearch | 9.4.0 <= 9.4.3 | affected |
| Elastic | Elasticsearch | 8.0.0 <= 8.19.18 | affected |
Weaknesses
- CWE-617: CWE-617 Reachable Assertion
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.