GHSA-ghfh-p92w-j4mg

Suggest an improvement
Source
https://github.com/advisories/GHSA-ghfh-p92w-j4mg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-ghfh-p92w-j4mg
Aliases
Downstream
CGA (22)
MINI (2)
Published
2025-04-08T18:34:42Z
Modified
2026-09-25T17:45:04Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Details

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash.

A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-09T13:02:50Z",
    "nvd_published_at":  "2025-04-08T17:15:34Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.elasticsearch:elasticsearch-grok

Package

Name
org.elasticsearch:elasticsearch-grok
View open source insights on deps.dev
Purl
pkg:maven/org.elasticsearch/elasticsearch-grok

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.17.0
Fixed
8.15.1

Affected versions

8.*
8.5.0
8.5.1
8.5.2
8.5.3
8.6.0
8.6.1
8.6.2
8.7.0
8.7.1
8.8.0
8.8.1
8.8.2
8.9.0
8.9.1
8.9.2
8.10.0
8.10.1
8.10.2
8.10.3
8.10.4
8.11.0
8.11.1
8.11.2
8.11.3
8.11.4
8.12.0
8.12.1
8.12.2
8.13.0
8.13.1
8.13.2
8.13.3
8.13.4
8.14.0
8.14.1
8.14.2
8.14.3
8.15.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json"