ElasticsearchGHSA-ghfh-p92w-j4mg
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Medium6.5CVE-2024-52980 · Published Apr 8, 2025 · updated Sep 10, 2026
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.17.0, < 8.15.1 | 8.15.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-elasticsearch-2024-52980, CVE-2024-52980
- nvd.nist.gov/vuln/detail/CVE-2024-52980
- github.com/elastic/elasticsearch/commit/4e5c6801f4d60f100f122072f6bf35b21fd722a5
- github.com/elastic/elasticsearch/commit/a02dc7165c75f12701f8d47a2bdefe5283735267
- discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919
- github.com/elastic/elasticsearch
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 102025 | Elasticsearch: Insertion of Sensitive Information into Log File via reindex API | Medium5.7 | 8.18.8+3 more |
| May 12025 | Elasticsearch Uncontrolled Resource Consumption Vulnerability | Medium6.5 | 7.17.25+1 more |
| Apr 82025 | Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion | Medium4.9 | 7.17.24+1 more |
| Jan 212025 | Elasticsearch allocation of resources without limits or throttling leads to crash | Medium6.5 | 7.17.21+1 more |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability | Medium | 8.16.2 |
| Jul 312024 | Elasticsearch stores private key on disk unencrypted | Medium4.9 | 7.17.23+1 more |