Memory Exhaustion in Elasticsearch by Authenticated Users
CVE-2026-72678
6.5MEDIUM
What is CVE-2026-72678?
Elasticsearch contains a flaw where it does not properly validate the size value derived from user input before utilizing it for memory allocation. This issue allows an authenticated user with merely read privileges to craft a specific request that forces the Elasticsearch node into making an overly large memory allocation attempt. This can lead to memory exhaustion, causing a fatal error and resulting in denial of service for that node, ultimately impacting the health of the entire cluster. This vulnerability can be triggered by a single request, making it particularly concerning as it bypasses the need for excessive workloads to exploit.
Affected Version(s)
Elasticsearch 8.19.0 <= 8.19.19
Elasticsearch 9.4.0 <= 9.4.4
Elasticsearch 9.5.0