CVE-2026-56148

EUVD-2026-41065
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.8%
Affected Products (NVD)
VendorProductVersion
elasticelasticsearch
8.0.0 ≤
𝑥
< 8.19.17
elasticelasticsearch
9.0.0 ≤
𝑥
< 9.3.6
elasticelasticsearch
9.4.0 ≤
𝑥
< 9.4.3
𝑥
= Vulnerable software versions