Memory Allocation Vulnerability in Elasticsearch by Elastic
CVE-2026-72656
6.5MEDIUM
What is CVE-2026-72656?
A vulnerability exists in Elasticsearch's ES|QL query processing that allows an authenticated user to send a specially crafted query. This can trigger excessive memory allocation, leading to denial of service by exhausting heap memory on the receiving node. As a result, the affected node may become unavailable, disrupting normal operations.
Affected Version(s)
Elasticsearch 8.11.0 <= 8.17.9