Skip to content
ElasticsearchGHSA-ghfh-p92w-j4mg

Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function

Medium6.5CVE-2024-52980 · Published Apr 8, 2025 · updated Sep 10, 2026

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.17.0, < 8.15.18.15.1
Details and references

More Elasticsearch advisories

All Elasticsearch
Advisory
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Medium5.7Oct 10, 2025
Elasticsearch Uncontrolled Resource Consumption Vulnerability
Medium6.5May 1, 2025
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
Medium4.9Apr 8, 2025
Elasticsearch allocation of resources without limits or throttling leads to crash
Medium6.5Jan 21, 2025
Elasticsearch Incorrect Authorization vulnerability
MediumDec 17, 2024
Elasticsearch stores private key on disk unencrypted
Medium4.9Jul 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.