Medium severity6.5NVD Advisory· Published Aug 13, 2026· Updated Sep 1, 2026
CVE-2026-72645
CVE-2026-72645
Description
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted search request that causes an excessively large memory allocation, exhausting the JVM heap and terminating the affected node.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- osv-coords9 versionspkg:apk/wolfi/ruby3.4-elasticsearchpkg:apk/wolfi/ruby4.0-elasticsearchpkg:bitnami/elasticsearchpkg:apk/chainguard/ruby3.3-elasticsearchpkg:apk/chainguard/ruby3.2-elasticsearchpkg:apk/wolfi/ruby3.2-elasticsearchpkg:apk/chainguard/ruby4.0-elasticsearchpkg:apk/wolfi/ruby3.3-elasticsearchpkg:apk/chainguard/ruby3.4-elasticsearch
< 0+ 8 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: >= 8.0.0, < 8.19.20
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
1News mentions
1- Elasticsearch: Twelve DoS Vulnerabilities Disclosed Together, One High SeverityVypr Intelligence · Aug 13, 2026