Impact
Uncontrolled Resource Consumption (CWE-400) in Elastic's Elasticsearch allows an attacker to trigger excessive allocation of system resources, which can exhaust memory or CPU and bring the affected nodes or the entire cluster offline. The vulnerability is manifested when the system accepts requests that lead to large or infinite data allocations without sufficient safeguards, thus breaking availability for legitimate users.
Affected Systems
The vulnerability affects Elastic's Elasticsearch product. No specific version range is identified in the data provided, so all deployments of Elasticsearch that may not have applied the latest security patch are potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate threat level, and the lack of an EPSS score suggests that current evidence of exploitation is insufficient. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed large‑scale attacks yet. Based on the description, the likely attack vector is a remote request to Elasticsearch’s HTTP API that triggers excessive allocation, meaning an external attacker could exploit the flaw from outside the cluster without needing privileged access.
OpenCVE Enrichment