Impact
Elasticsearch is vulnerable to uncontrolled resource consumption (CWE‑400). A crafted request can force the system to allocate excessive memory or CPU resources, causing the node or cluster to become unresponsive. The primary impact is a denial of service that can affect all users relying on the cluster for data indexing and search.
Affected Systems
Elastic Elasticsearch is the affected product. No specific affected version information is supplied, so any Elasticsearch deployment that has not applied the latest security update may be susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, but the vulnerability is not listed in CISA KEV. The likely attack vector is remote, via the REST‑API endpoints that accept search or aggregation queries; a malicious actor could send large or complex requests to trigger the resource spike. Exploitation requires network access to the cluster and does not require authentication, so systems exposed to the internet pose the highest risk.
OpenCVE Enrichment