Uncontrolled Resource Consumption in Elasticsearch Affects Multiple Versions
CVE-2026-63263
6.5MEDIUM
What is CVE-2026-63263?
A vulnerability in Elasticsearch allows authenticated users to exploit the system through specially crafted queries sent to the ES|QL engine, resulting in uncontrolled resource consumption. This can lead to denial of service, as the exponential CPU usage from these queries persists even after the initial request is completed. Consequently, repeated submissions can completely deplete the available query worker resources, leading to unserviceable ES|QL queries until the affected node is manually restarted.
Affected Version(s)
Elasticsearch 9.4.0 <= 9.4.3
Elasticsearch 9.0.0 <= 9.3.7
Elasticsearch 8.0.0 <= 8.19.18