Impact
The vulnerability is an uncontrolled resource consumption flaw (CWE‑400) in Elasticsearch. When exploited, a malicious or malformed query can force the cluster to allocate excessive memory, causing the node to become unresponsive and ultimately resulting in a denial‑of‑service condition. The weakness arises from insufficient validation of query payloads that trigger large data structures. Consequently, the confidentiality and integrity of the cluster remain unaffected, but the availability of the indexed services is compromised.
Affected Systems
The flaw affects Elasticsearch instances produced by Elastic. No specific version ranges are listed in the CNA data; therefore, based on the available CNA data, it is inferred that any deployed Elasticsearch server that has not applied the recent security updates may be vulnerable. Refer to the discussion thread for guidance on which releases contain the fix.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates a medium severity vulnerability. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Based on the description, it is inferred that the likely attack vector is remote and requires network connectivity to the cluster, with the attacker able to send crafted queries to trigger memory exhaustion. If unmitigated, any adversary could cause repeated outages, impacting service availability.
OpenCVE Enrichment