Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.
{
"cna_assigner": "elastic",
"cwe_ids": [
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72656.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.11.0"
},
{
"last_affected": "8.17.9"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72656.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"208511009835985317180580355053232355922",
"234524355310133257468696357063662032497",
"259276949594656983910150105029939680243",
"271964186908149063341075619131659320749",
"223456071764145691648024898018688778761",
"233361839235492011046063144465997703847",
"337710482818487754337798007728537277766",
"73001732600831682918777362956602333564",
"45531697802446254036933836779969854572",
"284850839330347593716497543479372528819",
"253153743745374922979229523676973936659",
"117291883901458337904525777344847570345",
"262701314133867649444116024155002849741",
"18193197316722835622501889156185042034",
"193130682827659610084798487920558095971",
"273964929925145743838236083560647829932",
"313959147821951195364223995217851726460",
"285454846534183156614583894498644241859",
"85385765914580435985082443160609440467",
"56286279675503731480801116862084289346",
"86421015749809518963379423667357500804",
"332564840511257249348351372297812439705",
"272442834782317023820571881414896247395",
"281868523671389613138177415295605422896",
"276785651251256242690884838564340922335",
"230212800701782605430105338053274912138",
"271380480992148703025975724900140149827",
"75079943764912969988806776813090722213",
"211723223235694157821157297656865508807",
"60641004449869267060455429202906709647",
"178707780334109799420275501407544648132",
"75249252295291359655416797193409147148",
"201208164447275145247064592864955936736",
"263406865216178711944738147493243472030",
"183394704611755183266701093542379993801",
"192178534569215456036007927099342211421",
"297125306947348135144018897184163575671",
"302187857933986355197177755807512258103",
"159071128329531074288790684597659687307",
"170238312508647195459857081625537965732",
"331713653478682415137354547056372157210",
"302476738835161081923390293093899274344",
"189403952929623185717701410784385594864",
"56689861616340704609940234474623544868",
"141762084839637016734461649760860863400",
"316625176835235480414935441807737453425",
"18559619679208654075637854918847320362",
"206409949337864746469039510288475654745",
"211966884652188642442148958736598622712",
"243058464834419981869143710827628253511",
"51174866609467016062137172011005783319",
"176316158426484999903201253025256432235"
],
"threshold": 0.9
},
"id": "CVE-2026-72656-ad06248f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/04e979aa50b657bebd4a0937389308de82c2bdad",
"target": {
"file": "libs/entitlement/qa/entitlement-test-plugin/src/main/java/org/elasticsearch/entitlement/qa/test/RestEntitlementsCheckAction.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "290974461469073037565015802088281157473",
"length": 881
},
"id": "CVE-2026-72656-e28467d5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/04e979aa50b657bebd4a0937389308de82c2bdad",
"target": {
"file": "libs/entitlement/qa/entitlement-test-plugin/src/main/java/org/elasticsearch/entitlement/qa/test/RestEntitlementsCheckAction.java",
"function": "getTestEntries"
}
}
]
"2026-09-06T08:14:58Z"