PT-2026-71757 · Elastic · Elasticsearch

CVE-2026-72639

·

Published

2026-08-13

·

Updated

2026-09-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Elasticsearch (affected versions not specified)
Description An issue exists where the software does not enforce an upper bound on a user-supplied count accepted by a search highlighting option. Because the resulting allocation is not accounted against any circuit breaker, an authenticated user with read privileges on a single searchable index can send a small search request that forces the node to reserve an excessively large internal data structure. This allocation happens before highlighting safety limits are evaluated, leading to memory exhaustion and a fatal error that terminates the node process. This results in a denial of service for the affected node and degrades cluster routing and health. The issue is not volumetric and does not depend on the size of the indexed data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2026-72639
CVE-2026-72639

Affected Products

Elasticsearch