Junglewise Threat Intelligence

CVE-2026-72636: Elastic Elasticsearch uncontrolled recursion in wildcard matching

CVE-2026-72636 · Severity: medium · CVSS 6.5 · Published 2026-08-13

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a popular search and analytics engine used by organizations to index and query large volumes of data, contains a flaw in its wildcard pattern matching logic. An authenticated user can craft a specially designed search query containing deeply nested wildcard patterns that causes the affected Elasticsearch node to exhaust its stack memory and crash, disrupting search and analytics services for the entire deployment.

Technical details

The vulnerability is an uncontrolled recursion (CWE-674) in Elasticsearch's wildcard pattern matching helper, which lacks bounds on recursion depth or total match operations. An attacker with valid credentials can send a search request with a wildcard pattern containing a large number of wildcard groups evaluated against sufficiently long names, exhausting the thread stack. When stack overflow occurs, Elasticsearch treats it as an unrecoverable condition and terminates the node rather than failing gracefully, resulting in a denial of service. The flaw affects Elasticsearch versions 8.0.0 through 8.19.19 and 9.0.0 through 9.4.4, and is resolved in versions 8.19.20 and 9.4.5.

Affected products

  • Elastic Elasticsearch 8.0.0 through 8.19.19, 9.0.0 through 9.4.4

Timeline

  • 2026-08-13: disclosed: Publicly disclosed via Elastic security advisory ESA-2026-133
  • 2026-08-13: patched: Fixed in Elasticsearch 8.19.20 and 9.4.5

References

Related threats