AZL-106721

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106721.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106721
Upstream
  • CVE-2026-102411
Published
2026-10-06T20:17:13Z
Modified
2026-10-07T14:17:13Z
Summary
CVE-2026-102411 affecting package rubygem-elasticsearch 8.9.0-1
Details

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such resources are retrieved together. A user holding the manage_index_templates cluster privilege can register multiple resources each within the individual limit. Retrieving them together materializes all of their metadata values in memory at once, exhausting available heap and causing the affected node to fail with an out-of-memory error, resulting in a denial of service.

References

Affected packages

Azure Linux:3 / rubygem-elasticsearch

Package

Name
rubygem-elasticsearch
Purl
pkg:rpm/azure-linux/rubygem-elasticsearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.9.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106721.json"