CVE-2026-63144
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deployments, this results in complete service outage; in multi-node clusters, it causes repeated node restarts and sustained availability degradation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 9.4.0 <= 9.4.3 | affected |
| Elastic | Elasticsearch | 9.3.0 <= 9.3.7 | affected |
| Elastic | Elasticsearch | 8.19.0 <= 8.19.18 | affected |
Weaknesses
- CWE-674: CWE-674 Uncontrolled Recursion
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.