Impact
Elasticsearch contains an uncontrolled recursion flaw (CWE‑674) that, when triggered by an authenticated user submitting a specially crafted query, causes excessive allocation of resources while the request is processed. This leads to a denial of service by draining memory and CPU, potentially rendering the affected node unavailable for all clients.
Affected Systems
The vulnerability affects Elastic’s Elasticsearch component. Any node running a version covered by the security advisory linked in the references list may be vulnerable. The exact version ranges are detailed in the advisory, but no specific version list is provided in the CVE data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. Because an attacker must be authenticated to submit the crafted query, only users with permission can launch the attack. Based on the description, it is inferred that exposed nodes could become unavailable not only to the attacker but also to other legitimate users, thereby impacting service availability. The issue is not listed in CISA’s KEV catalog.
OpenCVE Enrichment