Elasticsearch Excessive Memory Allocation Vulnerability Leading to Denial-of-Service

Vulnerability

A vulnerability allowing excessive memory allocation has been identified in Elasticsearch. This issue arises from the allocation of resources without limits or throttling, and can be exploited by an authenticated user with snapshot restore privileges. The vulnerability allows for crafted HTTP requests to cause excessive memory use, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability causes excessive memory consumption, leading to a denial-of-service condition where the application becomes unresponsive or unavailable.

Remediation

Users can upgrade to Elasticsearch versions 8.19.8, 9.1.8, or 9.2.2 to address this vulnerability.

Added: Dec 18, 2025, 11:19 PM
Updated: Dec 18, 2025, 11:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
4.4
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.