ElasticsearchGHSA-2cqf-6xv9-f22w
Elasticsearch vulnerable to Uncontrolled Resource Consumption
High7.5CVE-2023-31418 · Published Oct 26, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | < 7.17.13 | 7.17.13 |
| >= 8.0.0, < 8.9.0 | 8.9.0 |
Details and references
An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch node to exit with an OutOfMemory error by sending a moderate number of malformed HTTP requests. The issue was identified by Elastic Engineering and we have no indication that the issue is known or that it is being exploited in the wild.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-elasticsearch-2023-31418, CVE-2023-31418
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 262023 | Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2 | Medium4.1 | 7.17.13, 8.9.2 |
| Oct 262023 | Elasticsearch vulnerable to stack overflow in the search API CVE-2023-31419Medium6.5fixed in 7.17.13, 8.9.1 | Medium6.5 | 7.17.13, 8.9.1 |
| Nov 222023 | Elasticsearch Improper Handling of Exceptional Conditions CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3 | Medium6.5 | 7.17.14, 8.10.3 |
| Mar 272024 | Elasticsearch Uncontrolled Resource Consumption vulnerability CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0 | Medium4.9 | 7.17.19, 8.13.0 |
| Mar 272024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-23451Medium4.4fixed in 8.13.0 | Medium4.4 | 8.13.0 |
| Mar 292024 | Elasticsearch Uncaught Exception leading to crash CVE-2024-23449Medium4.3fixed in 8.11.1 | Medium4.3 | 8.11.1 |