Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/elasticsearch-8-18-0-9-0-0-security-update-esa-2026-111/389495 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 20:17
Updated : 2026-09-04 20:17
NVD link : CVE-2026-72656
Mitre link : CVE-2026-72656
CVE.ORG link : CVE-2026-72656
JSON object : View
Products Affected
elastic
- elasticsearch
CWE
CWE-789
Memory Allocation with Excessive Size Value
