Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that terminates the Elasticsearch node. The condition can be triggered repeatedly, including by queries embedded in shared resources, causing persistent cluster unavailability. | |
| Title | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-10-06T19:57:23.769Z
Reserved: 2026-09-29T02:06:02.425Z
Link: CVE-2026-102404
Updated: 2026-10-06T19:57:19.296Z
Status : Received
Published: 2026-10-06T20:17:12.333
Modified: 2026-10-06T20:17:12.333
Link: CVE-2026-102404
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:45:06Z
-
CWE-400
Uncontrolled Resource Consumption