Description
Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating their computational complexity or bounding their execution time. An authenticated user with read access to any text-based index can submit a specially crafted regular expression that triggers catastrophic backtracking, consuming excessive CPU on Elasticsearch worker threads and degrading query throughput for other tenants on the affected node. The cluster does not crash as a result of this issue.
Published: 2026-10-06
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An inefficient regular expression – a CWE-1333 weakness – in the ES|QL CHUNK function lets an authenticated user with read access submit a crafted pattern that triggers catastrophic backtracking. The recursive chunking strategy uses the supplied regex as a text‑splitting separator without validating its computational cost, which can cause worker threads to consume large amounts of CPU. The exhaustion of processing resources degrades query throughput for other tenants but does not crash the cluster. This results in a denial of service condition for legitimate users on the affected node.

Affected Systems

Elastic Elasticsearch is the sole vendor and product affected. Versions that include the ES|QL CHUNK function without the documented patch – such as releases prior to 8.19.22, 9.4.8, or 9.5.5 – are vulnerable. No specific product version list is given beyond the reference to these four releases.

Risk and Exploitability

The CVSS score of 4.3 indicates low‑medium severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation data. The attack likely occurs over authenticated queries that use the vulnerable ES|QL function, meaning an attacker must first have legitimate read privileges. Because the vulnerability does not crash the cluster, it is harder to detect but can be exploited to exhaust resources and deny service to other tenants.

Generated by OpenCVE AI on October 6, 2026 at 20:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Elasticsearch to the latest patched release (8.19.22, 9.4.8, or 9.5.5) that addresses the regex complexity issue.
  • If an upgrade is not immediately feasible, limit or validate user‑supplied regular expressions in ES|QL queries, for example by enforcing a maximum length or restricting disallowed constructs to prevent catastrophic backtracking.
  • Monitor CPU usage and query latency on the Elasticsearch nodes, and apply rate limiting or alerting for patterns of repeated high‑CPU queries that could indicate an attempted denial‑of‑service attack.

Generated by OpenCVE AI on October 6, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating their computational complexity or bounding their execution time. An authenticated user with read access to any text-based index can submit a specially crafted regular expression that triggers catastrophic backtracking, consuming excessive CPU on Elasticsearch worker threads and degrading query throughput for other tenants on the affected node. The cluster does not crash as a result of this issue.
Title Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:56:06.441Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102408

cve-icon Vulnrichment

Updated: 2026-10-06T19:56:00.587Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:12.777

Modified: 2026-10-06T20:17:12.777

Link: CVE-2026-102408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity