CVE-2026-72656
EUVD-2026-5827913.08.2026, 20:17
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 8.11.0 ≤ 𝑥 < 8.18.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration