6.5
CVE-2026-102411
- EPSS 0.3%
- Veröffentlicht 06.10.2026 19:31:43
- Zuletzt bearbeitet 07.10.2026 13:42:52
- Erkennungen
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such resources are retrieved together. A user holding the *manage_index_templates* cluster privilege can register multiple resources each within the individual limit. Retrieving them together materializes all of their metadata values in memory at once, exhausting available heap and causing the affected node to fail with an out-of-memory error, resulting in a denial of service.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerElastic
≫
Produkt
Elasticsearch
Default Statusunaffected
Version <=
8.19.22
Version
8.0.0
Status
affected
Version <=
9.4.6
Version
9.0.0
Status
affected
Version <=
9.5.2
Version
9.5.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.211 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@elastic.co | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-3-8-19-23-security-update-esa-2026-192/390865