Memory Allocation Flaw in Elasticsearch by Elastic
CVE-2026-72684
6.5MEDIUM
What is CVE-2026-72684?
A vulnerability in Elasticsearch enables an authenticated user with only read privileges to execute a specially crafted search request. This request leads to uncontrolled memory allocation in an internal component, bypassing existing memory accounting controls. The resultant out-of-memory condition can crash the affected node, resulting in a denial of service.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.19
Elasticsearch 9.0.0 <= 9.4.4