CVE-2026-102404: Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that terminates the Elasticsearch node. The condition can be triggered repeatedly, including by queries embedded in shared resources, causing persistent cluster unavailability.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with low privileges can trigger the condition. No user interaction is required, and the attack can be delivered over the network through a specially crafted query.
What is the operational impact?
The crafted query can cause uncontrolled memory growth during query processing, leading to an out-of-memory condition that terminates an Elasticsearch node. Repeated triggering, including through queries embedded in shared resources, can result in persistent cluster unavailability.
Can the issue be repeatedly triggered after a node recovers?
Yes. The condition can be triggered repeatedly, and queries embedded in shared resources can continue to cause disruption, potentially keeping the cluster unavailable.