Threats Tagged 'cve-2026-63140'
View all threats tagged with 'cve-2026-63140'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-63140'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-63140: CWE-617 Reachable Assertion in Elastic ElasticsearchCVE-2026-63140 0 Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node. Join the discussion | CVE Database V5 | 07/21/2026, 21:04:01 UTC Added: 07/21/2026, 21:07:52 UTC |
Showing 1 to 1 of 1 result