Impact
Uncontrolled resource consumption in Elasticsearch allows an attacker with search privileges to craft a query that forces the data node to allocate more heap memory than is available, leading to node unavailability and degraded cluster performance. The resulting denial of service can render the cluster unusable until manual intervention restores service.
Affected Systems
Elastic:Elasticsearch is the only vendor product listed. The vendor discussion reference points to security updates for releases 8.19.15, 9.2, 9.9, and 3.4, indicating that older versions lacking these patches are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description the attack vector is remote over HTTPS, requiring the attacker to possess search privileges and to send a specially crafted JSON query that drives the node into excessive memory allocation, resulting in a crash or unresponsive state.
OpenCVE Enrichment