Description
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Elasticsearch contains a memory allocation flaw that allows an authenticated user with connector management privileges to create connector resources whose "description" field can be set to a size that exceeds the allowed maximum, leading the cluster to allocate an uncontrolled amount of memory. When these resources are accessed, the node may exhaust its heap memory and crash, causing a denial of service to applications relying on the cluster.

Affected Systems

Elastic:Elasticsearch is affected. No specific version limits are listed, so all supported releases that allow companion connectors and do not yet have the relevant patch could be vulnerable.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity level. The exploit probability (EPSS) is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires ‑ authentication and connector‑management privileges; the attacker must create a connector with a very large description and subsequently access it to trigger the crash. Due to these prerequisites, the practical risk is limited to environments where such privileged users exist but is still significant because a single user can take the entire cluster offline.

Generated by OpenCVE AI on October 6, 2026 at 20:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Elasticsearch patch or upgrade to a version that includes the vulnerability fix, such as the 8.19.x security update mentioned in the vendor advisory.
  • If a patch is not yet available, restrict or disable connector‑management privileges for users until the fix can be applied, preventing attacker‑controlled connector creation.
  • Consider configuring or enforcing limits on the "description" field size through custom validation or by adjusting cluster architecture to isolate connector resources, thereby mitigating the memory allocation risk before a patch is released.

Generated by OpenCVE AI on October 6, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.
Title Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:53:45.426Z

Reserved: 2026-09-29T20:57:38.467Z

Link: CVE-2026-103005

cve-icon Vulnrichment

Updated: 2026-10-06T19:53:41.119Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:13.597

Modified: 2026-10-06T20:17:13.597

Link: CVE-2026-103005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value