CVE-2026-103008: Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes geometry values produced by scripted runtime fields. Unlike geometry supplied as text, which is subject to a nesting-depth limit, geometry constructed from a script's output is not bounded. An authenticated user with read access to a single index can submit a request defining such a field with a script that produces a deeply nested structure. Processing this request recurses past the available stack space, causing the affected node to terminate. The node does not recover automatically on all deployments and may require manual intervention to restore service.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with read access to a single index can exploit it. No additional privileges or user interaction are required.
What request triggers the denial of service?
The attacker submits a request defining a scripted runtime field whose script produces a deeply nested geometry structure. Elasticsearch builds and serializes that script-produced geometry without a recursion-depth bound, potentially exhausting the stack and terminating the node.
Are all deeply nested geometry inputs affected?
No. Geometry supplied as text is subject to a nesting-depth limit. The exposed path is geometry constructed from a script's output for a scripted runtime field.
What happens after a vulnerable node crashes?
The affected node may terminate after recursion exceeds available stack space. It does not recover automatically in all deployments, so restoring service may require manual intervention.