6.5
CVE-2026-102409
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:40
- Zuletzt bearbeitet 07.10.2026 13:42:52
- Erkennungen
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElastic
≫
Produkt
Elasticsearch
Default Statusunaffected
Version <=
9.2.8
Version
9.2.0
Status
affected
Version <=
9.3.8
Version
9.3.0
Status
affected
Version <=
9.4.7
Version
9.4.0
Status
affected
Version <=
9.5.4
Version
9.5.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.21 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-674 Uncontrolled Recursion
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
https://discuss.elastic.co/t/elasticsearch-9-4-8-9-5-5-security-update-esa-2026-190/390863