# Elasticsearch 8.19.21, 9.4.6, 9.5.2 Security Update (ESA-2026-196)

**URL:** <https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-2-security-update-esa-2026-196/390870>\
**Category:** Security Announcements\
**Created:** [October 6, 2026, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-2-security-update-esa-2026-196/390870 "2026-10-06T18:50:30Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [October 6, 2026, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-2-security-update-esa-2026-196/390870/1 "2026-10-06T18:50:30Z")

</div>

**Uncontrolled Recursion in Elasticsearch Leading to Denial of Service**

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API.

Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.

**Affected Versions:**

> - 8.x: All versions from 8.0.0 up to and including 8.19.20
> - 9.x:

- All versions from 9.0.0 up to and including 9.4.5
- All versions from 9.5.0 up to and including 9.5.1

**Affected Configurations:**

> - All configurations are affected. The vulnerable code path is part of Elasticsearch's search aggregation functionality, which is enabled by default.

**Solutions and Mitigations:**

The issue is resolved in versions 8.19.21, 9.4.6, and 9.5.2.

The versions above are the first releases verified to contain the fix. Elastic recommends upgrading to one of these fixed versions or a later release verified to contain the fix, and reviewing the known issues for your target version before upgrading.

**For Users that Cannot Upgrade:**

> - There are no workarounds for this vulnerability.

**Indicators of Compromise (IOC)**

No specific indicators of compromise have been identified for this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**CVE ID:** CVE-2026-103006  
**Problem Type:** CWE-674 - Uncontrolled Recursion
