Elasticsearch 9.4.8, 9.5.5 Security Update (ESA-2026-190)

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).

Affected Versions:

  • 9.x:
  • All versions from 9.2.0 up to and including 9.2.8
  • All versions from 9.3.0 up to and including 9.3.8
  • All versions from 9.4.0 up to and including 9.4.7
  • All versions from 9.5.0 up to and including 9.5.4

No fix is available for the 9.2.x or 9.3.x release lines. Users should upgrade to a supported release line.

Users on the 8.x release line are not affected. The text chunking functionality that contains this vulnerability was introduced in a 9.x release and is not present in 8.x.

Users on the 9.0.x and 9.1.x release lines are not affected. The text chunking functionality that contains this vulnerability was introduced in 9.2.0 and is not present in these release lines.

Affected Configurations:

  • Elasticsearch deployments where ES|QL is enabled (enabled by default) and where authenticated users with low-privileged index read access can submit queries.

Solutions and Mitigations:

The issue is resolved in versions 9.4.8 and 9.5.5.

The versions above are the first releases that contain the fix, and later releases also contain it. Elastic recommends upgrading to the most recent release available, and reviewing the known issues for your target version before upgrading.

For Users that Cannot Upgrade:

  • There are no workarounds for this vulnerability.

Indicators of Compromise (IOC)

No specific indicators of compromise have been identified for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-102409
Problem Type: CWE-674 - Uncontrolled Recursion