Impact
Elasticsearch contains a memory allocation flaw that allows an authenticated user with connector management privileges to create connector resources whose "description" field can be set to a size that exceeds the allowed maximum, leading the cluster to allocate an uncontrolled amount of memory. When these resources are accessed, the node may exhaust its heap memory and crash, causing a denial of service to applications relying on the cluster.
Affected Systems
Elastic:Elasticsearch is affected. No specific version limits are listed, so all supported releases that allow companion connectors and do not yet have the relevant patch could be vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity level. The exploit probability (EPSS) is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires ‑ authentication and connector‑management privileges; the attacker must create a connector with a very large description and subsequently access it to trigger the crash. Due to these prerequisites, the practical risk is limited to environments where such privileged users exist but is still significant because a single user can take the entire cluster offline.
OpenCVE Enrichment