Description
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Assess Impact
AI Analysis

Impact

Elasticsearch contains an uncontrolled recursion flaw that allows an authenticated user with read access to submit a deeply nested aggregation request. Processing this request triggers unbounded recursive calls, exhausting the node's memory and CPU, and causes the node to terminate. The process does not restart automatically, requiring manual intervention to restore service.

Affected Systems

Elasticsearch, by Elastic

Risk and Exploitability

The vulnerability receives a CVSS score of 6.5, indicating a moderate severity. Exploit probability data is not available and the flaw is not listed in CISA’s KEV catalog. The attack requires an authenticated user with the ability to use the search aggregation endpoint, typically over the cluster network. Once executed, the attacker can cause a local or remote denial of service without escalating privileges.

Generated by OpenCVE AI on October 6, 2026 at 20:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Elasticsearch security update that addresses uncontrolled recursion, following the guidance in the official Elastic discussion post
  • Limit or disable aggregation features for users who do not need them, or enforce a maximum depth restriction on aggregation queries
  • Monitor cluster logs for unusually deep aggregation requests and set alerts to detect potential abuse

Generated by OpenCVE AI on October 6, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.
Title Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:53:22.509Z

Reserved: 2026-09-29T20:57:38.467Z

Link: CVE-2026-103006

cve-icon Vulnrichment

Updated: 2026-10-06T19:53:18.840Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:13.730

Modified: 2026-10-06T20:17:13.730

Link: CVE-2026-103006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:30:05Z

Weaknesses