Impact
Elasticsearch contains an uncontrolled recursion flaw that allows an authenticated user to submit a specifically crafted query. When processed, the query causes the server to repeatedly allocate resources, leading to excessive memory and CPU usage that ultimately renders the node unavailable.
Affected Systems
The vulnerability affects the Elasticsearch component of Elastic. Any node running a version covered by the linked security advisory is potentially vulnerable. The advisory lists the affected releases, so deployers should verify their version against that list.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. Because the issue requires proper credentials, only authenticated users can trigger the denial of service. The vulnerability is not listed in CISA’s KEV catalog. Even though successful attacks are considered unlikely, the impact on availability can be significant for exposed nodes.
OpenCVE Enrichment