Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2026-56145
6.5MEDIUM
What is CVE-2026-56145?
A vulnerability in Elasticsearch allows a low-privileged authenticated user to execute specially crafted EQL sequence queries, potentially causing excessive memory consumption and leading to a denial of service. This issue arises when the user interacts with an index they control, resulting in the application crashing due to resource overutilization.
Affected Version(s)
Elasticsearch 9.4.0 <= 9.4.3
Elasticsearch 8.0.0 <= 8.19.17
Elasticsearch 9.0.0 <= 9.3.6