CVE-2024-52979: Elastic Elasticsearch

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

Affected products

  • Elastic Elasticsearch: before 7.17.25 (fixed in 7.17.25); from 8.0.0, before 8.16.0 (fixed in 8.16.0)

Published 2025-05-01. Last modified 2026-06-17.