CLEANSTART-2026-BL83922

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-BL83922.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-BL83922
Upstream
Published
2026-10-06T00:39:11Z
Modified
2026-10-08T16:47:04Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker
Details

Security vulnerability affects the sonarqube package. Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker.

References

Affected packages

CleanStart / sonarqube

Package

Name
sonarqube
Purl
pkg:apk/cleanstart/sonarqube

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.6.0.123539-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-BL83922.json"