CVE-2026-72638

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially crafted, malformed custom analysis definition that is resolved recursively without a cycle or depth check, exhausting the thread stack and terminating the affected node.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-13 20:17

Updated : 2026-09-01 14:21


NVD link : CVE-2026-72638

Mitre link : CVE-2026-72638

CVE.ORG link : CVE-2026-72638


JSON object : View

Products Affected

elastic

  • elasticsearch
CWE
CWE-674

Uncontrolled Recursion