BIT-elasticsearch-2026-72686

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2026-72686.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-elasticsearch-2026-72686
Aliases
Published
2026-08-19T08:39:50Z
Modified
2026-09-08T08:47:15Z
Summary
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Details

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of the value being validated, so the validation causes the thread to exhaust its stack. The resulting fatal error is not handled by the surrounding execution paths and terminates the affected node process, producing a denial of service.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:maven:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / elasticsearch

Package

Name
elasticsearch
Purl
pkg:bitnami/elasticsearch

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.19.20
Introduced
9.0.0
Fixed
9.4.5
Introduced
9.5.0
Fixed
9.5.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/elasticsearch/BIT-elasticsearch-2026-72686.json"