Impact
Elasticsearch allows a user with the manage_index_templates cluster privilege to create many templates, each with metadata limited in size but without a cumulative memory cap. If numerous such templates are retrieved together, all their metadata is deserialized into heap space, potentially exhausting the node’s memory and causing an out‑of‑memory error that shuts down the node. The primary effect is a denial of service to the affected Elasticsearch cluster, impacting availability for users and applications that rely on search services.
Affected Systems
Elastic:Elasticsearch. No specific version range is supplied, but the vulnerability exists in any release that allows unbounded aggregation of template metadata before deserialization.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity and EPSS is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires cluster‑level privilege (manage_index_templates), so an attacker would need an authenticated user with that privilege or the ability to grant it. Once privileged, the attacker can create many templates and trigger the denial of service by resolving them together. Based on the description, it is inferred that there is no external attack vector; the risk is therefore largely confined to insiders or compromised accounts, though the impact of a service outage can be significant.
OpenCVE Enrichment