Uncontrolled Resource Consumption in Elasticsearch by Elastic
CVE-2026-94408
4.9MEDIUM
What is CVE-2026-94408?
A vulnerability in Elasticsearch has been identified that allows for uncontrolled resource consumption, potentially leading to denial of service. This issue arises from improper handling of resource allocation, which can be exploited to exhaust system resources, disrupting service availability. Organizations using affected versions should take immediate action to mitigate potential risks and enhance their cybersecurity posture.
Affected Version(s)
Elasticsearch 8.0.0 <= 8.19.21
Elasticsearch 9.0.0 <= 9.4.6
Elasticsearch 9.5.0 <= 9.5.2