CVE-2026-63140
Description
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- osv-coords9 versionspkg:apk/wolfi/ruby3.2-elasticsearchpkg:apk/chainguard/ruby3.3-elasticsearchpkg:bitnami/elasticsearchpkg:apk/chainguard/ruby3.4-elasticsearchpkg:apk/wolfi/ruby3.3-elasticsearchpkg:apk/wolfi/ruby3.4-elasticsearchpkg:apk/chainguard/ruby4.0-elasticsearchpkg:apk/wolfi/ruby4.0-elasticsearchpkg:apk/chainguard/ruby3.2-elasticsearch
< 9.5.0-r0+ 8 more
- (no CPE)range: < 9.5.0-r0
- (no CPE)range: < 9.5.0-r0
- (no CPE)range: >= 8.0.0, < 8.19.19
- (no CPE)range: < 9.5.0-r1
- (no CPE)range: < 9.5.0-r0
- (no CPE)range: < 9.5.0-r1
- (no CPE)range: < 9.5.0-r0
- (no CPE)range: < 9.5.0-r0
- (no CPE)range: < 9.5.0-r0
cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*range: >=8.0.0,<8.19.19
- (no CPE)
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.