Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published Jul 21, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.42%
Description
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource exhaustion persists beyond query completion, repeated requests can fully exhaust the available query worker resources, rendering ES|QL queries unavailable until the node is restarted.
Affected products
-
- Version 8.0.0StatusaffectedConstraints<=8.19.18
- Version 9.0.0StatusaffectedConstraints<=9.3.7
- Version 9.4.0StatusaffectedConstraints<=9.4.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Elastic | Elasticsearch | unaffected |
|
- ≥ 8.0.0 · < 8.19.19
- ≥ 9.0.0 · < 9.3.8
- ≥ 9.4.0 · < 9.4.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-74/388577 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-74/388577 | Vendor Advisory |
Change history (0)
No recorded changes yet.