CVE-2025-68390: Elasticsearch Allocation of Resources Without Limits or Throttling
Published Dec 18, 2025
·Updated
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Affected Software
10 affected componentsFixes available
Elastic Elasticsearch
maven/org.elasticsearch.plugin:x-pack-core>=9.2.0<9.2.2
9.2.2
maven/org.elasticsearch.plugin:x-pack-core>=9.0.0<9.1.8
9.1.8
maven/org.elasticsearch.plugin:x-pack-core<8.19.8
8.19.8
Microsoft azl3 rubygem-elasticsearch 8.9.0-1
Microsoft cbl2 rubygem-elasticsearch 8.3.0-1
Elastic Elasticsearch>=7.0.0<=7.17.29
Elastic Elasticsearch>=8.0.0<8.19.8
Elastic Elasticsearch>=9.0.0<9.1.8
Elastic Elasticsearch>=9.2.0<9.2.2
Event History
Dec 18, 2025
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 19, 2025
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionSeverityWeaknessAffected Software
Dec 20, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68390?
CVE-2025-68390 has a high severity rating due to its potential for denial of service.
2
How do I fix CVE-2025-68390?
To fix CVE-2025-68390, upgrade to the latest version of Elasticsearch that addresses this vulnerability.
3
Who is affected by CVE-2025-68390?
CVE-2025-68390 primarily affects users of Elasticsearch with snapshot restore privileges.
4
What type of vulnerability is CVE-2025-68390?
CVE-2025-68390 is an allocation of resources without limits or throttling vulnerability.
5
What impact does CVE-2025-68390 have?
CVE-2025-68390 can lead to excessive memory allocation and potential denial of service.