Impact
This vulnerability is an instance of uncontrolled resource consumption (CWE‑400). An attacker can craft requests that cause the Elasticsearch cluster to allocate excessive memory, leading to resource exhaustion and service disruption. The impact is a denial‑of‑service that may affect the availability of search services for the entire cluster.
Affected Systems
The flaw affects Elastic’s Elasticsearch product. No specific versions are listed; refer to vendor support for details.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote; a malicious client could send oversized or malformed queries to trigger the excessive allocation. The exploitation does not require authentication or privileged access, and the risk is moderate, though it could degrade service availability substantially if left unmitigated.
OpenCVE Enrichment