CVE-2026-63136

EUVD-2026-46404
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
elasticelasticsearch
8.0.0 ≤
𝑥
< 8.19.15
elasticelasticsearch
9.0.0 ≤
𝑥
< 9.2.9
elasticelasticsearch
9.3.0 ≤
𝑥
< 9.3.4
𝑥
= Vulnerable software versions