Impact
An uncontrolled resource consumption flaw in Elasticsearch allows an attacker to trigger excessive allocation requests, potentially exhausting memory or thread pool resources. This leads to a denial of service of the Elasticsearch service. The weakness is identified as CWE‑400, indicating that improper input validation or resource limits enable the malicious behavior. The listed CVE description confirms that the exploit flow involves excessive allocation, categorized as CAPEC‑130.
Affected Systems
The vulnerability affects Elastic’s Elasticsearch product. No specific version numbers are provided in the data, so any instance of Elasticsearch that has not yet applied the cited security update may be at risk.
Risk and Exploitability
The CVSS score of 4.9 classifies this as a medium‑severity issue. The EPSS score is not available, so current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is not explicitly stated; based on the description it is inferred that it can be triggered through crafted requests or misconfigured cluster usage. Given the moderate severity and lack of known exploitation evidence, the risk is considered moderate, but any service exposed to untrusted input should treat it as potentially high impact due to the availability consequences.
OpenCVE Enrichment