CVE-2026-56143: Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Published Sep 1, 2026
·Updated
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.
Affected Software
1 affected component
Elasticsearch Elasticsearch
Event History
Sep 1, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
Exploitation requires a user with elevated privileges who can submit a specially crafted request.
2
What is the expected impact on an affected node?
The crafted request can cause excessive memory consumption and may render the affected node unavailable. The supplied impact metrics indicate an availability impact, with no confidentiality or integrity impact.