Executive brief
Elasticsearch, a widely used search and analytics engine, is vulnerable to a flaw that allows a user with basic search permissions to crash the service. By sending a specially crafted search request, an attacker can cause the system to enter an infinite processing loop, leading to a complete service outage or repeated system restarts. This disrupts business operations and data availability for all applications relying on the affected Elasticsearch cluster.
Technical details
An uncontrolled recursion vulnerability (CWE-674) exists in the Elasticsearch query evaluation component. An authenticated attacker with read-level index access can submit a specially crafted search request that triggers unbounded recursive processing. This leads to a fatal stack overflow or resource exhaustion error, terminating the affected node. In multi-node clusters, this results in sustained availability degradation and repeated node restarts. The issue is resolved in versions 8.19.19, 9.3.8, and 9.4.4.
Affected products
- Elastic Elasticsearch 8.19.0 to 8.19.18, 9.3.0 to 9.3.7, 9.4.0 to 9.4.3
Timeline
- 2026-07-21: advisory: Elastic security update ESA-2026-68 published
- 2026-07-21: patched: Fixes released in versions 8.19.19, 9.3.8, and 9.4.4