Description
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileges on a single searchable index can submit one small search request that causes the node to reserve an excessively large internal data structure. The allocation occurs before the existing highlighting safety limits are evaluated, so memory exhaustion raises a fatal error that terminates the Elasticsearch node process. This results in a denial of service for the affected node and degrades cluster routing and health. The defect is not volumetric and does not depend on the size of the indexed data, so a single request is sufficient.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Elasticsearch fails to impose an upper bound on a user‑supplied count used in a search highlighting request, and the resulting allocation is not subject to any circuit breaker. A single authenticated read‑only user can thus send a small search request that reserves an excessively large internal data structure, draining memory and causing a fatal error that terminates the node. This fault leads to a denial of service for the affected node and destabilises cluster routing and health. The weakness aligns with CWE‑789 – Unchecked Input Size or Buffer Size.

Affected Systems

The vulnerability applies to the Elastic:Elasticsearch product. Specific version information is not provided in the data, but a search highlighting configuration that accepts a count parameter without a hard limit will be affected. The attack can target any searchable index in the cluster, regardless of its size, and effectively requires only read‑level access to the index.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as medium severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating no known large‑scale exploitation. However, because the attack requires only a single request from an authenticated user with read rights, it is moderately easy to execute in environments where such access is broadly granted. The resulting node crash can bring the entire cluster offline, making it a significant operational threat. The absence of circuit‑breaker checks further lowers the barrier to exploitation, raising the risk when read‑only users are not tightly controlled.

Generated by OpenCVE AI on August 13, 2026 at 21:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Elasticsearch security patch that fixes the highlighting allocation bug (see Elastic’s discussion link for affected releases such as 8.19.20, 9.4.5, and 9.5.1).
  • If an immediate patch is not possible, temporarily disable highlighting in search queries for users who only require read access or remove the count parameter from such requests.
  • Implement application‑level checks or query‑time constraints to limit the highlight count to a safe, vetted value, reducing the risk of triggering the vulnerability if an older version must remain in use.

Generated by OpenCVE AI on August 13, 2026 at 21:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elasticsearch
Vendors & Products Elastic
Elastic elasticsearch

Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileges on a single searchable index can submit one small search request that causes the node to reserve an excessively large internal data structure. The allocation occurs before the existing highlighting safety limits are evaluated, so memory exhaustion raises a fatal error that terminates the Elasticsearch node process. This results in a denial of service for the affected node and degrades cluster routing and health. The defect is not volumetric and does not depend on the size of the indexed data, so a single request is sufficient.
Title Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Elastic Elasticsearch
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-08-13T20:28:15.250Z

Reserved: 2026-08-10T11:17:35.480Z

Link: CVE-2026-72639

cve-icon Vulnrichment

Updated: 2026-08-13T20:28:11.774Z

cve-icon NVD

Status : Received

Published: 2026-08-13T20:17:24.427

Modified: 2026-08-13T21:18:09.373

Link: CVE-2026-72639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:15:03Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value