OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-103006

MEDIUM · CVSS 6.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to an uncontrolled recursion issue in its search aggregation feature, allowing authenticated users with read access to submit deeply nested requests that can exhaust server resources. This can lead to a Denial of Service, as the affected node will terminate and require manual intervention for recovery. Organizations using Elasticsearch should prioritize patching this vulnerability to prevent potential service disruptions.

CVE
CVE-2026-103006
Severity
MEDIUM
CVSS
6.5
EPSS
0.40%

Original NVD Description

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)