Medium severity6.5NVD Advisory· Published Aug 13, 2026· Updated Sep 1, 2026
CVE-2026-72636
CVE-2026-72636
Description
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on the total number of match operations performed. A search request containing a wildcard pattern with a large number of wildcard groups, evaluated against a sufficiently long name, exhausts the thread stack. Elasticsearch treats a stack overflow as an unrecoverable condition and shuts the node down, so the request terminates the affected node rather than failing gracefully.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.19.20, <9.4.5
Patches
Vulnerability mechanics
References
1News mentions
1- Elasticsearch: Twelve DoS Vulnerabilities Disclosed Together, One High SeverityVypr Intelligence · Aug 13, 2026