Uncontrolled Recursion Vulnerability in Elasticsearch by Elastic.
CVE-2026-103008

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-103008?

A vulnerability exists in Elasticsearch that allows for uncontrolled recursion due to how the system constructs and serializes geometry values via scripted runtime fields. This issue enables authenticated users to issue specially crafted requests that result in deeply nested data structures. Since there is no limit on the recursion depth for these structures, processing them can exhaust the server's stack space, leading to a denial of service. Affected nodes may fail to recover automatically, necessitating manual intervention to restore service.

Affected Version(s)

Elasticsearch 8.12.0 <= 8.19.22

Elasticsearch 9.0.0 <= 9.4.7

Elasticsearch 9.5.0 <= 9.5.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.