ElasticsearchGHSA-mm3m-5497-xggg
Elasticsearch Uncontrolled Resource Consumption Vulnerability
Medium6.5CVE-2024-52979 · Published May 1, 2025 · updated Oct 2, 2025
Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | < 7.17.25 | 7.17.25 |
| >= 8.0.0-alpha1, < 8.16.0 | 8.16.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-elasticsearch-2024-52979, CVE-2024-52979
- nvd.nist.gov/vuln/detail/CVE-2024-52979
- github.com/elastic/elasticsearch/pull/114002
- github.com/elastic/elasticsearch/commit/cbde7f456d7ccd98556302fccf3238bb4557fc91
- github.com/elastic/elasticsearch/commit/f9b6b57d1d0f76e2d14291c04fb50abeb642cfbf
- discuss.elastic.co/t/elasticsearch-7-17-25-and-8-16-0-security-update-esa-2024-40/377709
- github.com/elastic/elasticsearch
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 152025 | Elasticsearch: improper authentication | Medium6.8 | 8.19.8+2 more |
| Oct 102025 | Elasticsearch: Insertion of Sensitive Information into Log File via reindex API | Medium5.7 | 8.18.8+3 more |
| Apr 82025 | Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion | Medium4.9 | 7.17.24+1 more |
| Apr 82025 | Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function | Medium6.5 | 8.15.1 |
| Jan 212025 | Elasticsearch allocation of resources without limits or throttling leads to crash | Medium6.5 | 7.17.21+1 more |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability | Medium | 8.16.2 |