Resource exhaustion in Elasticsearch - CVE-2026-63263
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the ES|QL engine when processing a specially crafted query. A remote user can submit a specially crafted query to cause a denial of service.
This affects deployments where users are able to execute ES|QL queries, and repeated requests can exhaust query worker resources until the node is restarted.