Impact
An inefficient regular expression – a CWE-1333 weakness – in the ES|QL CHUNK function lets an authenticated user with read access submit a crafted pattern that triggers catastrophic backtracking. The recursive chunking strategy uses the supplied regex as a text‑splitting separator without validating its computational cost, which can cause worker threads to consume large amounts of CPU. The exhaustion of processing resources degrades query throughput for other tenants but does not crash the cluster. This results in a denial of service condition for legitimate users on the affected node.
Affected Systems
Elastic Elasticsearch is the sole vendor and product affected. Versions that include the ES|QL CHUNK function without the documented patch – such as releases prior to 8.19.22, 9.4.8, or 9.5.5 – are vulnerable. No specific product version list is given beyond the reference to these four releases.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑medium severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation data. The attack likely occurs over authenticated queries that use the vulnerable ES|QL function, meaning an attacker must first have legitimate read privileges. Because the vulnerability does not crash the cluster, it is harder to detect but can be exploited to exhaust resources and deny service to other tenants.
OpenCVE Enrichment