BIT-elasticsearch-2026-63136

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2026-63136.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-elasticsearch-2026-63136
Aliases
Published
2026-07-28T08:53:02Z
Modified
2026-09-08T08:47:15Z
Summary
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Details

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.

Database specific
{
    "cpes": [
        "cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:maven:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / elasticsearch

Package

Name
elasticsearch
Purl
pkg:bitnami/elasticsearch

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.19.15
Introduced
9.0.0
Fixed
9.2.9
Introduced
9.4.0
Fixed
9.3.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2026-63136.json"