CVE-2026-56148: Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56148?
CVE-2026-56148 has a medium severity rating of 6.5.
How do I fix CVE-2026-56148?
To fix CVE-2026-56148, update to the latest version of Elasticsearch that includes the security patch.
What impact does CVE-2026-56148 have on my system?
CVE-2026-56148 can lead to a denial of service by causing excessive resource consumption, making the affected node unavailable.
Who is affected by CVE-2026-56148?
CVE-2026-56148 affects installations of Elasticsearch that allow authenticated users to submit specially crafted queries.
What type of vulnerability is CVE-2026-56148?
CVE-2026-56148 is classified as an uncontrolled recursion vulnerability, leading to excessive allocation issues.