Elasticsearch Uncontrolled Resource Consumption vulnerability
Description
A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A denial-of-service vulnerability in Elasticsearch allows a high-privileged attacker to crash an ingest node by sending a document through a deeply nested pipeline.
Vulnerability
Overview
CVE-2024-23450 is an uncontrolled resource consumption vulnerability in Elasticsearch. Processing a document through a deeply nested ingest pipeline on an ingest node causes the node to crash [1][4]. The root cause is uncontrolled resource consumption triggered by the excessive depth of pipeline processing, leading to a crash [1].
Exploitation
To exploit this vulnerability, an attacker must have high privileges (such as an ingest user) and the ability to submit a document to a deeply nested pipeline [4]. No user interaction is required beyond submitting the crafted request, and the attack is performed over the network [4]. The vulnerability affects Elasticsearch versions 7.0.0 to 7.17.19 and 8.0.0 to 8.13.0 [4].
Impact
Successful exploitation results in a denial-of-service condition, causing the Elasticsearch node to crash [1][4]. This can disrupt service availability by crashing a node, potentially affecting cluster stability if the node is critical.
Mitigation
Elastic has released fixed versions: 7.17.19 and 8.13.0 [4]. Users should upgrade to these versions or later to remediate the vulnerability. No workarounds are mentioned in available sources. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.elasticsearch:elasticsearchMaven | >= 7.0.0, < 7.17.19 | 7.17.19 |
org.elasticsearch:elasticsearchMaven | >= 8.0.0, < 8.13.0 | 8.13.0 |
Affected products
142- osv-coords141 versionspkg:apk/chainguard/elasticsearch-8pkg:apk/chainguard/elasticsearch-8-bitnamipkg:apk/chainguard/elasticsearch-8-configpkg:apk/chainguard/elasticsearch-8-iamguardedpkg:apk/chainguard/elasticsearch-configpkg:apk/chainguard/trinopkg:apk/chainguard/trino-configpkg:apk/chainguard/trino-oci-entrypointpkg:apk/chainguard/trino-plugin-accumulopkg:apk/chainguard/trino-plugin-ai-functionspkg:apk/chainguard/trino-plugin-atoppkg:apk/chainguard/trino-plugin-bigquerypkg:apk/chainguard/trino-plugin-blackholepkg:apk/chainguard/trino-plugin-cassandrapkg:apk/chainguard/trino-plugin-clickhousepkg:apk/chainguard/trino-plugin-delta-lakepkg:apk/chainguard/trino-plugin-druidpkg:apk/chainguard/trino-plugin-duckdbpkg:apk/chainguard/trino-plugin-elasticsearchpkg:apk/chainguard/trino-plugin-example-httppkg:apk/chainguard/trino-plugin-exasolpkg:apk/chainguard/trino-plugin-exchange-filesystempkg:apk/chainguard/trino-plugin-exchange-hdfspkg:apk/chainguard/trino-plugin-fakerpkg:apk/chainguard/trino-plugin-functions-pythonpkg:apk/chainguard/trino-plugin-geospatialpkg:apk/chainguard/trino-plugin-google-sheetspkg:apk/chainguard/trino-plugin-hivepkg:apk/chainguard/trino-plugin-http-event-listenerpkg:apk/chainguard/trino-plugin-http-server-event-listenerpkg:apk/chainguard/trino-plugin-hudipkg:apk/chainguard/trino-plugin-icebergpkg:apk/chainguard/trino-plugin-ignitepkg:apk/chainguard/trino-plugin-jmxpkg:apk/chainguard/trino-plugin-kafkapkg:apk/chainguard/trino-plugin-kafka-event-listenerpkg:apk/chainguard/trino-plugin-kinesispkg:apk/chainguard/trino-plugin-kudupkg:apk/chainguard/trino-plugin-lakehousepkg:apk/chainguard/trino-plugin-ldap-group-providerpkg:apk/chainguard/trino-plugin-local-filepkg:apk/chainguard/trino-plugin-lokipkg:apk/chainguard/trino-plugin-mariadbpkg:apk/chainguard/trino-plugin-memorypkg:apk/chainguard/trino-plugin-mlpkg:apk/chainguard/trino-plugin-mongodbpkg:apk/chainguard/trino-plugin-mysqlpkg:apk/chainguard/trino-plugin-mysql-event-listenerpkg:apk/chainguard/trino-plugin-opapkg:apk/chainguard/trino-plugin-openlineagepkg:apk/chainguard/trino-plugin-opensearchpkg:apk/chainguard/trino-plugin-oraclepkg:apk/chainguard/trino-plugin-password-authenticatorspkg:apk/chainguard/trino-plugin-phoenix5pkg:apk/chainguard/trino-plugin-pinotpkg:apk/chainguard/trino-plugin-postgresqlpkg:apk/chainguard/trino-plugin-prometheuspkg:apk/chainguard/trino-plugin-rangerpkg:apk/chainguard/trino-plugin-raptor-legacypkg:apk/chainguard/trino-plugin-redispkg:apk/chainguard/trino-plugin-redshiftpkg:apk/chainguard/trino-plugin-resource-group-managerspkg:apk/chainguard/trino-plugin-session-property-managerspkg:apk/chainguard/trino-plugin-singlestorepkg:apk/chainguard/trino-plugin-snowflakepkg:apk/chainguard/trino-plugin-spooling-filesystempkg:apk/chainguard/trino-plugin-sqlserverpkg:apk/chainguard/trino-plugin-teradata-functionspkg:apk/chainguard/trino-plugin-thriftpkg:apk/chainguard/trino-plugin-tpcdspkg:apk/chainguard/trino-plugin-tpchpkg:apk/chainguard/trino-plugin-verticapkg:apk/wolfi/trinopkg:apk/wolfi/trino-configpkg:apk/wolfi/trino-oci-entrypointpkg:apk/wolfi/trino-plugin-accumulopkg:apk/wolfi/trino-plugin-ai-functionspkg:apk/wolfi/trino-plugin-atoppkg:apk/wolfi/trino-plugin-bigquerypkg:apk/wolfi/trino-plugin-blackholepkg:apk/wolfi/trino-plugin-cassandrapkg:apk/wolfi/trino-plugin-clickhousepkg:apk/wolfi/trino-plugin-delta-lakepkg:apk/wolfi/trino-plugin-druidpkg:apk/wolfi/trino-plugin-duckdbpkg:apk/wolfi/trino-plugin-elasticsearchpkg:apk/wolfi/trino-plugin-example-httppkg:apk/wolfi/trino-plugin-exasolpkg:apk/wolfi/trino-plugin-exchange-filesystempkg:apk/wolfi/trino-plugin-exchange-hdfspkg:apk/wolfi/trino-plugin-fakerpkg:apk/wolfi/trino-plugin-functions-pythonpkg:apk/wolfi/trino-plugin-geospatialpkg:apk/wolfi/trino-plugin-google-sheetspkg:apk/wolfi/trino-plugin-hivepkg:apk/wolfi/trino-plugin-http-event-listenerpkg:apk/wolfi/trino-plugin-http-server-event-listenerpkg:apk/wolfi/trino-plugin-hudipkg:apk/wolfi/trino-plugin-icebergpkg:apk/wolfi/trino-plugin-ignitepkg:apk/wolfi/trino-plugin-jmxpkg:apk/wolfi/trino-plugin-kafkapkg:apk/wolfi/trino-plugin-kafka-event-listenerpkg:apk/wolfi/trino-plugin-kinesispkg:apk/wolfi/trino-plugin-kudupkg:apk/wolfi/trino-plugin-lakehousepkg:apk/wolfi/trino-plugin-ldap-group-providerpkg:apk/wolfi/trino-plugin-local-filepkg:apk/wolfi/trino-plugin-lokipkg:apk/wolfi/trino-plugin-mariadbpkg:apk/wolfi/trino-plugin-memorypkg:apk/wolfi/trino-plugin-mlpkg:apk/wolfi/trino-plugin-mongodbpkg:apk/wolfi/trino-plugin-mysqlpkg:apk/wolfi/trino-plugin-mysql-event-listenerpkg:apk/wolfi/trino-plugin-opapkg:apk/wolfi/trino-plugin-openlineagepkg:apk/wolfi/trino-plugin-opensearchpkg:apk/wolfi/trino-plugin-oraclepkg:apk/wolfi/trino-plugin-password-authenticatorspkg:apk/wolfi/trino-plugin-phoenix5pkg:apk/wolfi/trino-plugin-pinotpkg:apk/wolfi/trino-plugin-postgresqlpkg:apk/wolfi/trino-plugin-prometheuspkg:apk/wolfi/trino-plugin-rangerpkg:apk/wolfi/trino-plugin-raptor-legacypkg:apk/wolfi/trino-plugin-redispkg:apk/wolfi/trino-plugin-redshiftpkg:apk/wolfi/trino-plugin-resource-group-managerspkg:apk/wolfi/trino-plugin-session-property-managerspkg:apk/wolfi/trino-plugin-singlestorepkg:apk/wolfi/trino-plugin-snowflakepkg:apk/wolfi/trino-plugin-spooling-filesystempkg:apk/wolfi/trino-plugin-sqlserverpkg:apk/wolfi/trino-plugin-teradata-functionspkg:apk/wolfi/trino-plugin-thriftpkg:apk/wolfi/trino-plugin-tpcdspkg:apk/wolfi/trino-plugin-tpchpkg:apk/wolfi/trino-plugin-verticapkg:bitnami/elasticsearchpkg:maven/org.elasticsearch/elasticsearch
< 8.13.1-r0+ 140 more
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 8.13.1-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: < 444-r0
- (no CPE)range: >= 7.0.0, < 7.17.19
- (no CPE)range: >= 7.0.0, < 7.17.19
- Range: 7.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/advisories/GHSA-w5gg-2q56-6h4fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23450ghsaADVISORY
- discuss.elastic.co/t/elasticsearch-8-13-0-7-17-19-security-update-esa-2024-06/356314ghsaWEB
- security.netapp.com/advisory/ntap-20240517-0010ghsaWEB
- www.elastic.co/community/securityghsaWEB
- security.netapp.com/advisory/ntap-20240517-0010/mitre
News mentions
0No linked articles in our index yet.