CVE-2026-103008: Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

Published Oct 6, 2026
·
Updated

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes geometry values produced by scripted runtime fields. Unlike geometry supplied as text, which is subject to a nesting-depth limit, geometry constructed from a script's output is not bounded. An authenticated user with read access to a single index can submit a request defining such a field with a script that produces a deeply nested structure. Processing this request recurses past the available stack space, causing the affected node to terminate. The node does not recover automatically on all deployments and may require manual intervention to restore service.

Affected Software

1 affected component
Elastic Elasticsearch

Event History

Oct 6, 2026
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user with read access to a single index can exploit it. No additional privileges or user interaction are required.

2

What request triggers the denial of service?

The attacker submits a request defining a scripted runtime field whose script produces a deeply nested geometry structure. Elasticsearch builds and serializes that script-produced geometry without a recursion-depth bound, potentially exhausting the stack and terminating the node.

3

Are all deeply nested geometry inputs affected?

No. Geometry supplied as text is subject to a nesting-depth limit. The exposed path is geometry constructed from a script's output for a scripted runtime field.

4

What happens after a vulnerable node crashes?

The affected node may terminate after recursion exceeds available stack space. It does not recover automatically in all deployments, so restoring service may require manual intervention.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203