Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2026-72679
6.5MEDIUM
What is CVE-2026-72679?
A vulnerability in Elasticsearch allows an authenticated user with read-only permissions to exploit the input length restriction of user-supplied patterns in intervals queries. This issue can lead to unbounded recursion, exhausting the thread stack and causing fatal errors that terminate the Elasticsearch node process. As a result, the node experiences a denial of service, impacting its availability. The threat is particularly concerning as it can be triggered with minimal effort through a small search request.
Affected Version(s)
Elasticsearch 8.19.0 <= 8.19.19
Elasticsearch 9.0.0 <= 9.4.4