Impact
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch allows a low‑privileged authenticated user to submit a crafted query that causes the query‑processing engine to allocate memory without bounds. The resulting memory pressure brings the node to an out‑of‑memory state, terminating the process and rendering the cluster unavailable. Repeated exploitation of the same query can lead to persistent denial of service.
Affected Systems
Affected are Elastic Elasticsearch instances that have not applied the recent security update. The vulnerability is known in the 8.x and 9.x families; any deployment that accepts arbitrary queries from low‑privileged accounts is at risk. The product is Elastic:Elasticsearch, and the fix is distributed through the official Elastic Security Advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so a definitive exploitation probability cannot be quantified; however, the lack of a KEV listing suggests no widespread public exploitation yet. The attack requires authenticated access, making it relatively constrained but still dangerous in multi‑tenant or shared tenancy environments where an attacker may have limited permissions to submit queries. Monitor for repeated anomalous query patterns and ensure user privileges are restrained.
OpenCVE Enrichment