Allocation of Resources Without Limits or Throttling in Elasticsearch - CVE-2026-56143
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in Elasticsearch when handling specially crafted requests. A remote privileged user can submit a specially crafted request to cause a denial of service.
The issue may cause excessive memory consumption and render the affected node unavailable.