Uncontrolled Recursion in Elasticsearch Affects Denial of Service
CVE-2026-72638
6.5MEDIUM
What is CVE-2026-72638?
A flaw in Elasticsearch allows an authenticated user with low-privileged index creation permissions to exploit uncontrolled recursion. By submitting a specially crafted request containing a malformed custom analysis definition, this action can exhaust the thread stack, potentially overheating the system and leading to a denial of service. This vulnerability emphasizes the importance of thorough input validation and limits on recursion depth to maintain service stability.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.19
Elasticsearch 9.0.0 <= 9.4.4