Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-72656

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
Версия от 8.11.0 (включая) до 8.18.0 (исключая)

EPSS

Процентиль: 23%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-789

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 месяца назад

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

CVSS3: 6.5
github
около 1 месяца назад

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

EPSS

Процентиль: 23%
0.00296
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-789