Impact
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch allows a user with elevated privileges to submit a specially crafted machine‑learning request that forces the cluster to allocate a large amount of memory, exhausting node RAM and rendering the instance unavailable; the resulting memory exhaustion disables service operation for that node, causing a denial of service for all functions that rely on it.
Affected Systems
Elastic:Elasticsearch is affected; the CVE entry does not specify a version range, so any deployed instance of Elasticsearch may be at risk until an official patch is applied.
Risk and Exploitability
The CVSS score of 4.9 and an EPSS score of less than 1% indicate a low, but nonzero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires elevated privileges and the ability to submit machine‑learning requests, making it unlikely that an unprivileged attacker can exploit the flaw remotely. If such privileges are obtained, a crafted request may exhaust memory, causing service disruption and reducing cluster availability.
OpenCVE Enrichment