CVE-2026-72685
EUVD-2026-5824913.08.2026, 20:17
A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time, degrading the availability of indexing operations on the affected node.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elastic | elasticsearch | 8.0.0 ≤ 𝑥 < 8.19.20 |
| elastic | elasticsearch | 9.0.0 ≤ 𝑥 < 9.4.5 |
𝑥
= Vulnerable software versions