Reachable assertion in Elasticsearch - CVE-2026-63140
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to reachable assertion in query parsing when processing a specially crafted search request containing a null value in a specific query clause. A remote user can send a specially crafted search request to cause a denial of service.
Exploitation requires read access to at least one index. In single-node deployments this stops the service, while in multi-node clusters each successful exploit reduces cluster capacity for the affected node.