Vulnerability GHSA-gphj-4h6p-37xq

Medium Risk
MEDIUM RISK
CVSS Score: 4.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
9 months ago
December 19, 2025 at 12:31 AM UTC
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1 and 9.2.0 - 9.2.1

Summary

Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation

Details

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

Timeline

Published
9 months ago
December 19, 2025 at 12:31 AM UTC
Fixed (8.19.8)
Unknown
Unknown
Fixed (9.1.8)
Unknown
Unknown
Fixed (9.2.2)
Unknown
Unknown
Last Modified
18 days ago
September 10, 2026 at 03:50 AM UTC