CVE-2026-72638
EUVD-2026-5828413.08.2026, 20:17
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially crafted, malformed custom analysis definition that is resolved recursively without a cycle or depth check, exhausting the thread stack and terminating the affected node.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 8.0.0 ≤ 𝑥 < 8.19.20 |
| elastic | elasticsearch | 9.0.0 ≤ 𝑥 < 9.4.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration