Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that terminates the Elasticsearch node. The condition can be triggered repeatedly, including by queries embedded in shared resources, causing persistent cluster unavailability.
Affected Versions:
- 8.x: All versions from 8.0.0 up to and including 8.19.22
- 9.x:
- All versions from 9.0.0 up to and including 9.4.7
- All versions from 9.5.0 up to and including 9.5.4
Users on the 9.6.x release line are not affected. The vulnerability was fixed before the first release of the 9.6.x line.
Affected Configurations:
- All deployments where authenticated users can execute ES|QL queries. No special configuration is required beyond the default; the vulnerable behavior is present in all standard configurations.
Solutions and Mitigations:
The issue is resolved in versions 8.19.23, 9.4.8, 9.5.5.
The versions above are the first releases that contain the fix, and later releases also contain it. Elastic recommends upgrading to the most recent release available, and reviewing the known issues for your target version before upgrading.
For Users that Cannot Upgrade:
There are no workarounds for this vulnerability.
Indicators of Compromise (IOC)
No specific indicators of compromise have been identified for this vulnerability.
Elastic Cloud Serverless
Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.
Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-102404
Problem Type: CWE-400 - Uncontrolled Resource Consumption
Impact: CAPEC-130 - Excessive Allocation