Back to overview

CVE-2026-63136

MEDIUM
6.5
CVSS 3.1
Description
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.

Metadata

CVE ID
CVE-2026-63136
State
PUBLISHED
Assigner
elastic
Reserved
2026-07-15 18:23 UTC
Published
2026-07-21 20:20 UTC
Last updated
2026-07-21 20:20 UTC
Primary CWE
CWE-400
CWE-400 Uncontrolled Resource Consumption
Vendor / Product
Elastic / Elasticsearch
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products (1)
VendorProductPlatformVersions
Elastic Elasticsearch 8.0.0 ≤ 8.19.14, 9.3.0 ≤ 9.3.3, 9.0.0 ≤ 9.2.8
Weakness (CWE)
CWESourceDescription
CWE-400 cna CWE-400 Uncontrolled Resource Consumption
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Back to overview