CVE-2026-72656: Elastic Elasticsearch

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.

Affected products

  • Elastic Elasticsearch: from 8.11.0, before 8.18.0 (fixed in 8.18.0)

Published 2026-08-13. Last modified 2026-09-04.