Elasticsearch 8.19.20, 9.4.5 Security Update (ESA-2026-76)

Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation occurs outside the scope of the existing memory accounting controls that were intended to constrain it. The resulting out-of-memory condition is fatal and terminates the affected node process, causing a denial of service.

Affected Versions:

  • All versions from 8.0.0 up to and including 8.19.19
  • All versions from 9.0.0 up to and including 9.4.4

Affected Configurations:

  • All configurations are affected.

Solutions and Mitigations:

The issue is resolved in version 8.19.20 and 9.4.5.

For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-72684
Problem Type: CWE-770 - Allocation of Resources Without Limits or Throttling