Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deployments, this results in complete service outage; in multi-node clusters, it causes repeated node restarts and sustained availability degradation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.19.0, <= 8.19.18CPE match | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* | ||
>= 9.3.0, <= 9.3.7CPE match | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* | ||
>= 9.4.0, <= 9.4.3CPE match | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.