Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpg2-7m3g-5qc5

Опубликовано: 13 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

EPSS

Процентиль: 22%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-789

Связанные уязвимости

CVSS3: 6.5
redhat
28 дней назад

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

CVSS3: 6.5
nvd
28 дней назад

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

EPSS

Процентиль: 22%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-789