PT-2026-71788 · Elastic · Elasticsearch
CVE-2026-72678
·
Published
2026-08-13
·
Updated
2026-08-19
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Elasticsearch (affected versions not specified)
Description
An issue exists where the software fails to validate a size value from user-supplied input before using it to reserve memory for an internal data structure. An authenticated user with read privileges can send a single crafted request to a product API endpoint, triggering an excessively large memory allocation. This leads to memory exhaustion and a fatal error that terminates the node process, resulting in a denial of service and degraded cluster health. This issue is not volumetric, meaning a single request can trigger the failure regardless of the configured heap size.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elasticsearch