PT-2026-71757 · Elastic · Elasticsearch
CVE-2026-72639
·
Published
2026-08-13
·
Updated
2026-09-01
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Elasticsearch (affected versions not specified)
Description
An issue exists where the software does not enforce an upper bound on a user-supplied count accepted by a search highlighting option. Because the resulting allocation is not accounted against any circuit breaker, an authenticated user with read privileges on a single searchable index can send a small search request that forces the node to reserve an excessively large internal data structure. This allocation happens before highlighting safety limits are evaluated, leading to memory exhaustion and a fatal error that terminates the node process. This results in a denial of service for the affected node and degrades cluster routing and health. The issue is not volumetric and does not depend on the size of the indexed data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch