Denial of Service Vulnerability in Elasticsearch by Elastic
CVE-2026-72687
6.5MEDIUM
What is CVE-2026-72687?
A vulnerability in Elasticsearch allows a low-privileged authenticated user to exploit the system by submitting a specially crafted request containing a forged opaque identifier. This identifier is decoded and deserialized by Elasticsearch without adequate checks, leading to memory allocation that is unregulated. Consequently, this flaw can result in an out-of-memory condition, terminating the affected node process and resulting in denial of service for users relying on that instance.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.19
Elasticsearch 9.0.0 <= 9.4.4
Elasticsearch 9.5.0