CVE-2026-72687
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:11:00
- Zuletzt bearbeitet 01.09.2026 14:58:27
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the ...
CVE-2026-72686
- EPSS 0.36%
- Veröffentlicht 13.08.2026 19:10:58
- Zuletzt bearbeitet 01.09.2026 15:03:00
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of ...
CVE-2026-72685
- EPSS 0.26%
- Veröffentlicht 13.08.2026 19:10:56
- Zuletzt bearbeitet 01.09.2026 15:04:10
A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a dis...
CVE-2026-72684
- EPSS 0.29%
- Veröffentlicht 13.08.2026 19:10:53
- Zuletzt bearbeitet 01.09.2026 15:04:40
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upp...
CVE-2026-72683
- EPSS 0.36%
- Veröffentlicht 13.08.2026 19:10:51
- Zuletzt bearbeitet 01.09.2026 15:22:55
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to submit a request that causes a s...
CVE-2026-63263
- EPSS 0.24%
- Veröffentlicht 21.07.2026 23:10:49
- Zuletzt bearbeitet 03.08.2026 15:58:28
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumpt...
CVE-2026-63144
- EPSS 0.24%
- Veröffentlicht 21.07.2026 22:26:43
- Zuletzt bearbeitet 03.08.2026 16:07:28
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded ...
CVE-2026-63140
- EPSS 0.24%
- Veröffentlicht 21.07.2026 21:04:01
- Zuletzt bearbeitet 07.08.2026 20:08:43
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised duri...
CVE-2026-63136
- EPSS 0.24%
- Veröffentlicht 21.07.2026 20:20:07
- Zuletzt bearbeitet 07.08.2026 20:09:29
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available ...
CVE-2026-56145
- EPSS 0.3%
- Veröffentlicht 21.07.2026 20:17:02
- Zuletzt bearbeitet 07.08.2026 20:10:36
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can sen...