CVE-2026-72687: Elastic Elasticsearch
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the cluster, and a size value carried inside the identifier drives an allocation that is neither capped nor accounted for by the available memory-usage controls. The resulting out-of-memory condition is fatal and terminates the affected node process, resulting in a denial of service.
Affected products
- Elastic Elasticsearch: from 8.0.0, before 8.19.20 (fixed in 8.19.20); from 9.0.0, before 9.4.5 (fixed in 9.4.5); from 9.5.0, before 9.5.1 (fixed in 9.5.1)
Published 2026-08-13. Last modified 2026-09-01.