Skip to content
ElasticsearchGHSA-mm3m-5497-xggg

Elasticsearch Uncontrolled Resource Consumption Vulnerability

Medium6.5CVE-2024-52979 · Published May 1, 2025 · updated Oct 2, 2025

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
< 7.17.257.17.25
>= 8.0.0-alpha1, < 8.16.08.16.0
Details and references

More Elasticsearch advisories

All Elasticsearch
Advisory
Elasticsearch: improper authentication
Medium6.8Dec 15, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Medium5.7Oct 10, 2025
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
Medium4.9Apr 8, 2025
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Medium6.5Apr 8, 2025
Elasticsearch allocation of resources without limits or throttling leads to crash
Medium6.5Jan 21, 2025
Elasticsearch Incorrect Authorization vulnerability
MediumDec 17, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.