Uncontrolled Resource Consumption in Elasticsearch by Elastic
CVE-2026-63136

6.5MEDIUM

Key Information:

Vendor

Elastic

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-63136?

A vulnerability in Elasticsearch allows users with search privileges to issue specially crafted search requests that can excessively allocate resources on a data node. This leads to the exhaustion of available heap memory, resulting in node unavailability and overall degradation of the cluster's performance. Attackers can exploit this issue to induce downtime in the cluster, necessitating manual intervention to restore normal functionality.

Affected Version(s)

Elasticsearch 8.0.0 <= 8.19.14

Elasticsearch 9.3.0 <= 9.3.3

Elasticsearch 9.0.0 <= 9.2.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.