Unrated severityNVD Advisory· Published Jul 1, 2026· Updated Jul 1, 2026
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-49090
Description
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node unable to process requests.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.