Resource exhaustion in Elasticsearch - CVE-2025-68390
Published: December 19, 2025
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when restoring snapshot data. A remote user with snapshot restore privileges can trigger memory exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM Watson Discovery for IBM Cloud Pak for Data
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
How to mitigate CVE-2025-68390
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Assistant Cartridge - update to 5.4
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.4