Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service (CVE-2026-72656)
Description
CVE-2026-72656 is a medium severity vulnerability in Elasticsearch affecting versions from 8.11.0 up to but not including 8.17.10. It involves memory allocation with an excessive size value during ES|QL query processing, which can lead to denial of service by exhausting heap memory on the node. An authenticated user submitting a specially crafted ES|QL query can trigger this condition, causing the node to become unavailable.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from the ES|QL query processing component of Elasticsearch where an authenticated user can submit a query that causes an unbounded heap memory allocation. This excessive allocation can exhaust the available heap memory on the receiving node, resulting in denial of service. The issue is classified under CWE-789 (Memory Allocation with Excessive Size Value) and corresponds to CAPEC-130 (Excessive Allocation). The affected versions are Elasticsearch >=8.11.0 and <8.17.10. No CVSS score is provided, but the severity is assessed as medium. A patch is available for this vulnerability.
Potential Impact
Successful exploitation allows an authenticated user to cause denial of service by exhausting heap memory on an Elasticsearch node, making the node unavailable. This impacts the availability of the affected Elasticsearch service.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade Elasticsearch to version 8.17.10 or later to remediate the issue. Since this is not a cloud service, remediation requires applying the patch or upgrade manually. No known exploits are reported in the wild at this time.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-elasticsearch-2026-72656
- Osv Schema Version
- 1.6.2
- Aliases
- ["CVE-2026-72656"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- Medium
- State
- PUBLISHED
Threat ID: 6a85b4b2acd9273b492514bd
Added to database: 08/19/2026, 13:50:42 UTC
Last enriched: 08/19/2026, 14:11:10 UTC
Last updated: 10/04/2026, 10:04:19 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.