Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
Moderate severity
GitHub Reviewed
Published
Dec 19, 2025
to the GitHub Advisory Database
•
Updated Dec 19, 2025
Package
Affected versions
< 8.19.9
>= 9.0.0, < 9.1.9
>= 9.2.0, < 9.2.3
Patched versions
8.19.9
9.1.9
9.2.3
Description
Published by the National Vulnerability Database
Dec 18, 2025
Published to the GitHub Advisory Database
Dec 19, 2025
Reviewed
Dec 19, 2025
Last updated
Dec 19, 2025
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.
References