Uncontrolled Recursion Vulnerability in Elasticsearch by Elastic
CVE-2026-103006

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-103006?

An uncontrolled recursion issue in Elasticsearch allows for Denial of Service (DoS) when an authenticated user submits a uniquely crafted request featuring deeply nested aggregation definitions within the search API. This vulnerability exploits the search aggregation processing mechanism, leading to unbounded recursive execution that drains server resources. Consequently, the affected node can crash and requires manual intervention for service restoration. Organizations using Elasticsearch should take immediate steps to ensure their instances are secured against this vulnerability.

Affected Version(s)

Elasticsearch 8.0.0 <= 8.19.20

Elasticsearch 9.0.0 <= 9.4.5

Elasticsearch 9.5.0 <= 9.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.