CVE-2026-72656: Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service

Published Aug 13, 2026
·
Updated

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

Affected Software

1 affected component
Elasticsearch Elasticsearch

Event History

Aug 13, 2026
CVE Published
via MITRE·07:13 PM
Data Sourced
via MITRE·07:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-72656?

CVE-2026-72656 has a medium severity rating of 6.5.

2

How does CVE-2026-72656 affect Elasticsearch?

CVE-2026-72656 affects Elasticsearch by allowing an authenticated user to submit ES|QL queries that can lead to a denial of service due to excessive memory allocation.

3

What causes the vulnerability CVE-2026-72656?

CVE-2026-72656 is caused by memory allocation with an excessive size value in the ES|QL query processing component of Elasticsearch.

4

Who is impacted by CVE-2026-72656?

CVE-2026-72656 specifically impacts authenticated users of Elasticsearch who can submit ES|QL queries.

5

How can CVE-2026-72656 be mitigated?

Mitigation for CVE-2026-72656 involves applying the latest security updates provided by Elasticsearch to address the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203