#VU120207 Resource exhaustion in Elasticsearch - CVE-2025-68390
Published: December 19, 2025
Elasticsearch
Elastic Stack
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when restoring snapshot data. A remote user with snapshot restore privileges can trigger memory exhaustion and perform a denial of service (DoS) attack.