CVE-2026-49090
EUVD-2026-4110001.07.2026, 18:16
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 7.0.0 ≤ 𝑥 < 7.17.24 |
| elastic | elasticsearch | 8.0.0 ≤ 𝑥 < 8.15.0 |
𝑥
= Vulnerable software versions