Vulnerability GHSA-qf7c-7r9h-mm92

Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
9 months ago
December 19, 2025 at 12:31 AM UTC
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1
7.8.1 and 7.12.0 - 8.0.1 and 8.7.0 - 8.7.1

Summary

Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data

Details

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

Timeline

Published
9 months ago
December 19, 2025 at 12:31 AM UTC
Fixed (8.19.9)
Unknown
Unknown
Fixed (9.1.9)
Unknown
Unknown
Fixed (9.2.3)
Unknown
Unknown
Last Modified
18 days ago
September 10, 2026 at 03:50 AM UTC