CVE-2026-103005: Elastic Elasticsearch

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.

Affected products

  • Elastic Elasticsearch: from 8.12.0, before 8.19.23 (fixed in 8.19.23); from 9.0.0, up to and including 9.3.8; from 9.4.0, before 9.4.8 (fixed in 9.4.8); from 9.5.0, before 9.5.5 (fixed in 9.5.5)

Published 2026-10-06. Last modified 2026-10-09.