Elasticsearch 8.19.20, 9.4.5, 9.5.1 Security Update (ESA-2026-78)

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of the value being validated, so the validation causes the thread to exhaust its stack. The resulting fatal error is not handled by the surrounding execution paths and terminates the affected node process, producing a denial of service.

Affected Versions:

  • All versions from 8.0.0 up to and including 8.19.19
  • All versions from 9.0.0 up to and including 9.4.4
  • Version 9.5.0

Affected Configurations:

  • All configurations are affected.

Solutions and Mitigations:

The issue is resolved in version 8.19.20, 9.4.5, and 9.5.1.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-72686
Problem Type: CWE-674 - Uncontrolled Recursion