CVE-2026-56143: Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Published Sep 1, 2026
·Updated
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.
Other sources
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
— Microsoft
Affected Software
3 affected components
Elasticsearch Elasticsearch
Elastic Elasticsearch>=8.0.0<8.19.20
Elastic Elasticsearch>=9.0.0<9.3.0
Event History
Sep 1, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires a user with elevated privileges who can submit a specially crafted request.
2
What is the expected impact on an affected node?
The crafted request can cause excessive memory consumption and may render the affected node unavailable. The supplied impact metrics indicate an availability impact, with no confidentiality or integrity impact.