Uncontrolled Recursion Vulnerability in Elasticsearch by Elastic
CVE-2026-103006
6.5MEDIUM
What is CVE-2026-103006?
An uncontrolled recursion issue in Elasticsearch allows for Denial of Service (DoS) when an authenticated user submits a uniquely crafted request featuring deeply nested aggregation definitions within the search API. This vulnerability exploits the search aggregation processing mechanism, leading to unbounded recursive execution that drains server resources. Consequently, the affected node can crash and requires manual intervention for service restoration. Organizations using Elasticsearch should take immediate steps to ensure their instances are secured against this vulnerability.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.20
Elasticsearch 9.0.0 <= 9.4.5
Elasticsearch 9.5.0 <= 9.5.1