# Werid err: org..CircuitBreakingException: \[script\] Too many dynamic script compilations

**URL:** <https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153>\
**Category:** Elasticsearch\
**Created:** [May 18, 2020, 4:25pm UTC](https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153 "2020-05-18T16:25:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stanats](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@stanats](https://discuss.elastic.co/u/stanats)\
**Post date:** [May 18, 2020, 4:25pm UTC](https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153/1 "2020-05-18T16:25:19Z")

</div>

```auto
we are getting weird error : org.elasticsearch.common.breaker.CircuitBreakingException: [script] Too many dynamic script compilations within, max: [75/5m]; please use indexed, or scripts with parameters instead; this limit can be changed by the [script.max_compilations_rate] setting

[o.e.a.s.TransportSearchAction] [yyvrm-z] [testindex][2], node[yyvrm-zXSKGpvwChY5dm_Q], [P], s[STARTED], a[id
=M3POIs_SSqigKhUlwKZXYA]: Failed to execute [SearchRequest{searchType=QUERY_THEN_FETCH, indices=[], indicesOptions=IndicesOptions[ignore_unavailable=false, allow_no_indices=true, expa
nd_wildcards_open=true, expand_wildcards_closed=false, allow_aliases_to_multiple_indices=true, forbid_closed_indices=true, ignore_aliases=false, ignore_throttled=true], types=[], rout
ing='null', preference='null', requestCache=null, scroll=null, maxConcurrentShardRequests=15, batchedReduceSize=512, preFilterShardSize=128, allowPartialSearchResults=true, localClust
erAlias=null, getOrCreateAbsoluteStartMillis=-1, source={"size":1,"query":{"match_all":{"boost":1.0}},"script_fields":{"myscript":{"script":{"source":"java.lang.Math.class.forName(\"j
ava.lang.System\").getProperties()","lang":"painless"},"ignore_failure":false}}}}] lastShard [true]

We dont have "myscript" in our ES queries , is this something ES is doing internally ?
Please help

```

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [May 18, 2020, 4:34pm UTC](https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153/2 "2020-05-18T16:34:46Z")

</div>

> [@stanats](#):
>
> {"size":1,"query":{"match\_all":{"boost":1.0}},"script\_fields":{"myscript":{"script":{"source":"java.lang.Math.class.forName("j ava.lang.System").getProperties()","lang":"painless"}

Looks like someone is attempting to use an old Groovy security exploit on your cluster. See [Disable dynamic Groovy scripting by marking Groovy as not sandboxed · Issue #9655 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/9655) for more details.

Basically, that script was able to escalate privileges in older version of Elasticsearch that used Groovy (~4 years ago, in the 1.x series).

It's harmless today as the security vulnerability was A) patched and B) we don't use Groovy anymore (one of the main reasons we created Painless was to ensure it could be locked down from a security perspective). With that said, you should probably not allow users to inject arbitrary script fields or other portions of the query into the search request, just a matter of general safety.

---

<div class="post-metadata">

**Author:** ![stanats](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@stanats](https://discuss.elastic.co/u/stanats)\
**Post date:** [May 20, 2020, 2:44am UTC](https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153/3 "2020-05-20T02:44:25Z")

</div>

Thank you so much for the info.  
Can you please advice how to stop injecting arbitrary scripts /query part of search request ?

Thanks  
Stan

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [May 21, 2020, 3:16pm UTC](https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153/4 "2020-05-21T15:16:52Z")

</div>

That's mostly a front-end/UI operation. E.g. you need to either translate a user's request into the query DSL, or sanitize the input somehow. It's not the same as a SQL injection, but you can consider the manner of validation the same: don't ever let user input go directly into a SQL query (or an Elasticsearch query) without some kind of validation/sanitization.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 3:17pm UTC](https://discuss.elastic.co/t/werid-err-org-circuitbreakingexception-script-too-many-dynamic-script-compilations/233153/5 "2020-06-18T15:17:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
