Executive brief
Elasticsearch, a search and analytics engine used by enterprises to index and query large data volumes, contains a vulnerability that allows authenticated attackers to trigger excessive resource allocation. An attacker with valid credentials can craft requests that consume significant system resources, causing the service to become unresponsive or crash, disrupting business operations that depend on search and analytics availability.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) in Elasticsearch permits authenticated users to trigger denial of service via excessive memory or CPU allocation without authorization checks. The vulnerability requires authenticated access (PR:L) and network connectivity, affecting the availability of the search service. Patches are available in versions 8.19.22, 9.4.7, and 9.5.4.
Affected products
- Elastic Elasticsearch 8.0.0 to 8.19.21; 9.0.0 to 9.4.6; 9.5.0 to 9.5.3
- Elastic Elasticsearch 8.19.22, 9.4.7, 9.5.4 and later (patched)
Timeline
- 2026-09-26: disclosed: Published on NVD
- 2026-09-25: patched: Fixed in versions 8.19.22, 9.4.7, 9.5.4