SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63136

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to an uncontrolled resource consumption issue that allows users with search privileges to submit specially crafted search requests, leading to excessive heap memory allocation. This can result in denial of service, causing node unavailability and overall cluster degradation, which may require manual intervention to restore functionality. Organizations utilizing Elasticsearch should prioritize addressing this vulnerability to prevent potential downtime and service disruptions.

CVE
CVE-2026-63136
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)