CVE-2026-72684
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation occurs outside the scope of the existing memory accounting controls that were intended to constrain it. The resulting out-of-memory condition is fatal and terminates the affected node process, causing a denial of service.
| CWE | CWE-770 |
| Vendor | elastic |
| Product | elasticsearch |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 13, 2026 |
| Last Updated | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for elastic elasticsearch
Be the first to know when new medium vulnerabilities affecting elastic elasticsearch are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Elastic / Elasticsearch
8.0.0 โค 8.19.19 9.0.0 โค 9.4.4