Skip to content
ElasticCVE-2026-72647

Elasticsearch: denial of service

Medium6.5CVE-2026-72647 · Published Aug 13, 2026 · updated Sep 1, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request whose deeply nested structure is processed without a depth limit, exhausting the thread stack and terminating the affected node.

Elastic advisory

Affected versions

PackageAffectedFixed in
Elasticsearch
Product
>= 8.0.0, <= 8.19.19No fix yet
>= 9.0.0, <= 9.4.4No fix yet
Details and references

More Elastic advisories

All Elastic
Advisory
Elasticsearch: denial of service
Medium6.5Aug 13
A flaw in Elasticsearch
Medium4.3Aug 13
Elasticsearch: denial of service
Medium6.5Aug 13
Elasticsearch: denial of service
Medium6.5Aug 13
Elastic Kibana: denial of service
Medium6.5Aug 13
Elastic Kibana: missing authorization
High7.1Aug 13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.