Skip to content
ElasticsearchGHSA-2cqf-6xv9-f22w

Elasticsearch vulnerable to Uncontrolled Resource Consumption

High7.5CVE-2023-31418 · Published Oct 26, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
< 7.17.137.17.13
>= 8.0.0, < 8.9.08.9.0
Details and references

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400
Also known as
BIT-elasticsearch-2023-31418, CVE-2023-31418

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Oct 262023Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2
Oct 262023Elasticsearch vulnerable to stack overflow in the search API
CVE-2023-31419Medium6.5fixed in 7.17.13, 8.9.1
Nov 222023Elasticsearch Improper Handling of Exceptional Conditions
CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3
Mar 272024Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0
Mar 272024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-23451Medium4.4fixed in 8.13.0
Mar 292024Elasticsearch Uncaught Exception leading to crash
CVE-2024-23449Medium4.3fixed in 8.11.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.