Impact
Elasticsearch may consume excessive memory when a user executes a specially crafted EQL sequence query on an index they control, causing the node to crash. This uncontrolled resource consumption, identified as CWE-400, directly leads to a loss of availability for the affected Elasticsearch instance.
Affected Systems
Elasticsearch by Elastic is impacted. No specific version range was provided, so all installations that allow authenticated EQL sequence queries on controllable indexes should be considered vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS of less than 1%, indicating a moderate severity and a low likelihood of widespread exploitation. It is not listed in the CISA KEV catalog. The attack requires a low‑privileged authenticated user who has permission to run EQL queries; the exploit path involves sending a crafted query that triggers uncontrolled memory usage, culminating in a denial of service.
OpenCVE Enrichment