Skip to content
ElasticCVE-2026-72678

Elasticsearch: denial of service

Medium6.5CVE-2026-72678 · Published Aug 13, 2026 · updated Sep 1, 2026

Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that causes the node to attempt an excessively large allocation. The resulting memory exhaustion raises a fatal error that terminates the Elasticsearch node process, causing a denial of service for the affected node and degrading cluster health. The defect is not volumetric, so a single request is sufficient regardless of the heap size configured on the target node.

Elastic advisory

Affected versions

PackageAffectedFixed in
Elasticsearch
Product
>= 8.19.0, <= 8.19.19No fix yet
>= 9.4.0, <= 9.4.4No fix yet
<= 9.5.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-789

More Elastic advisories

All Elastic
Advisory
Elasticsearch: denial of service
Medium6.5Aug 13
A flaw in Elasticsearch
Medium4.3Aug 13
Elasticsearch: denial of service
Medium6.5Aug 13
Elasticsearch: denial of service
Medium6.5Aug 13
Elastic Kibana: denial of service
Medium6.5Aug 13
Elastic Kibana: missing authorization
High7.1Aug 13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.