Junglewise Threat Intelligence

CVE-2026-63144: Elastic Elasticsearch uncontrolled recursion in query evaluation component

CVE-2026-63144 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a widely used search and analytics engine, is vulnerable to a flaw that allows a user with basic search permissions to crash the service. By sending a specially crafted search request, an attacker can cause the system to enter an infinite processing loop, leading to a complete service outage or repeated system restarts. This disrupts business operations and data availability for all applications relying on the affected Elasticsearch cluster.

Technical details

An uncontrolled recursion vulnerability (CWE-674) exists in the Elasticsearch query evaluation component. An authenticated attacker with read-level index access can submit a specially crafted search request that triggers unbounded recursive processing. This leads to a fatal stack overflow or resource exhaustion error, terminating the affected node. In multi-node clusters, this results in sustained availability degradation and repeated node restarts. The issue is resolved in versions 8.19.19, 9.3.8, and 9.4.4.

Affected products

  • Elastic Elasticsearch 8.19.0 to 8.19.18, 9.3.0 to 9.3.7, 9.4.0 to 9.4.3

Timeline

  • 2026-07-21: advisory: Elastic security update ESA-2026-68 published
  • 2026-07-21: patched: Fixes released in versions 8.19.19, 9.3.8, and 9.4.4

References

Related threats