Elasticsearch Resource Allocation Vulnerability Leading to Denial-of-Service

Vulnerability

A vulnerability allowing excessive resource allocation has been identified in Elasticsearch. This issue can be exploited by low-privileged authenticated users who submit oversized user settings data, causing out-of-memory crashes and persistent denial-of-service conditions. The vulnerability arises from the application's lack of limits or throttling on resource allocation.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash due to out-of-memory errors.

Remediation

Users can upgrade to Elasticsearch versions 8.19.9, 9.1.9, or 9.2.3 to address this vulnerability.

Added: Dec 18, 2025, 10:18 PM
Updated: Dec 18, 2025, 10:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
4.9
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.