Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.
{
"cna_assigner": "elastic",
"cwe_ids": [
"CWE-400"
],
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.19.14"
},
{
"introduced": "9.3.0"
},
{
"last_affected": "9.3.3"
},
{
"introduced": "9.0.0"
},
{
"last_affected": "9.2.8"
}
]
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63136.json"
}"2026-08-09T08:05:10Z"
[
{
"target": {
"function": "testPromqlQueryWithConflictingTsTypesMarksFieldUnsupported",
"file": "x-pack/plugin/esql/src/test/java/org/elasticsearch/xpack/esql/analysis/AnalyzerTests.java"
},
"digest": {
"length": 601.0,
"function_hash": "84433789544010315812246774005552675939"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-63136-0b400218",
"source": "https://github.com/elastic/elasticsearch/commit/69a3e6c50ebb57a1fdbf3f235be9f11061ac7d86"
},
{
"target": {
"file": "x-pack/plugin/esql/src/test/java/org/elasticsearch/xpack/esql/analysis/AnalyzerTests.java"
},
"digest": {
"line_hashes": [
"234163232951028422978085367395355015356",
"336324895495804197828852394756872939000",
"283658986481949763179231452461160578552",
"90983762437915623732177975884360609784",
"201530536742802531269305682045005216476",
"171852364269482810748858037036789861963",
"314462254603794552743574645931750044692",
"295350290235740750339653402330741971858",
"214199429833385077961909239085936134582",
"165345166082600797091855140208265768837",
"68922472427642386306783373118438221572"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-63136-53609d75",
"source": "https://github.com/elastic/elasticsearch/commit/69a3e6c50ebb57a1fdbf3f235be9f11061ac7d86"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63136.json"