BIT-elasticsearch-2026-72684

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2026-72684.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-elasticsearch-2026-72684
Aliases
Published
2026-08-19T08:39:48Z
Modified
2026-09-08T08:47:24Z
Summary
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Details

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation occurs outside the scope of the existing memory accounting controls that were intended to constrain it. The resulting out-of-memory condition is fatal and terminates the affected node process, causing a denial of service.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:maven:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / elasticsearch

Package

Name
elasticsearch
Purl
pkg:bitnami/elasticsearch

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.19.21
Introduced
9.0.0
Fixed
9.4.6

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2026-72684.json"