CVE-2026-103005
EUVD-2026-9393506.10.2026, 20:17
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | elasticsearch | 8.12.0 ≤ 𝑥 ≤ 8.19.22 | CNA |
| elastic | elasticsearch | 9.0.0 ≤ 𝑥 ≤ 9.3.8 | CNA |
| elastic | elasticsearch | 9.4.0 ≤ 𝑥 ≤ 9.4.7 | CNA |
| elastic | elasticsearch | 9.5.0 ≤ 𝑥 ≤ 9.5.4 | CNA |
Common Weakness Enumeration