{"id":"CVE-2026-72656","summary":"Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service","details":"Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting the available heap on the receiving node and causing the node to become unavailable.","aliases":["BIT-elasticsearch-2026-72656"],"modified":"2026-09-06T08:14:58.564171Z","published":"2026-08-13T19:13:26.761Z","database_specific":{"cna_assigner":"elastic","cwe_ids":["CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72656.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"8.11.0"},{"last_affected":"8.17.9"}]}]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/elasticsearch-8-18-0-9-0-0-security-update-esa-2026-111/389495"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72656.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72656"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"d9ec3fa628c7b0ba3d25692e277ba26814820b20"},{"fixed":"04e979aa50b657bebd4a0937389308de82c2bdad"}],"database_specific":{"cpe":"cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.11.0"},{"fixed":"8.18.0"}],"source":"CPE_RANGE"}}],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["208511009835985317180580355053232355922","234524355310133257468696357063662032497","259276949594656983910150105029939680243","271964186908149063341075619131659320749","223456071764145691648024898018688778761","233361839235492011046063144465997703847","337710482818487754337798007728537277766","73001732600831682918777362956602333564","45531697802446254036933836779969854572","284850839330347593716497543479372528819","253153743745374922979229523676973936659","117291883901458337904525777344847570345","262701314133867649444116024155002849741","18193197316722835622501889156185042034","193130682827659610084798487920558095971","273964929925145743838236083560647829932","313959147821951195364223995217851726460","285454846534183156614583894498644241859","85385765914580435985082443160609440467","56286279675503731480801116862084289346","86421015749809518963379423667357500804","332564840511257249348351372297812439705","272442834782317023820571881414896247395","281868523671389613138177415295605422896","276785651251256242690884838564340922335","230212800701782605430105338053274912138","271380480992148703025975724900140149827","75079943764912969988806776813090722213","211723223235694157821157297656865508807","60641004449869267060455429202906709647","178707780334109799420275501407544648132","75249252295291359655416797193409147148","201208164447275145247064592864955936736","263406865216178711944738147493243472030","183394704611755183266701093542379993801","192178534569215456036007927099342211421","297125306947348135144018897184163575671","302187857933986355197177755807512258103","159071128329531074288790684597659687307","170238312508647195459857081625537965732","331713653478682415137354547056372157210","302476738835161081923390293093899274344","189403952929623185717701410784385594864","56689861616340704609940234474623544868","141762084839637016734461649760860863400","316625176835235480414935441807737453425","18559619679208654075637854918847320362","206409949337864746469039510288475654745","211966884652188642442148958736598622712","243058464834419981869143710827628253511","51174866609467016062137172011005783319","176316158426484999903201253025256432235"],"threshold":0.9},"id":"CVE-2026-72656-ad06248f","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/04e979aa50b657bebd4a0937389308de82c2bdad","target":{"file":"libs/entitlement/qa/entitlement-test-plugin/src/main/java/org/elasticsearch/entitlement/qa/test/RestEntitlementsCheckAction.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/04e979aa50b657bebd4a0937389308de82c2bdad","target":{"file":"libs/entitlement/qa/entitlement-test-plugin/src/main/java/org/elasticsearch/entitlement/qa/test/RestEntitlementsCheckAction.java","function":"getTestEntries"},"deprecated":false,"digest":{"length":881,"function_hash":"290974461469073037565015802088281157473"},"id":"CVE-2026-72656-e28467d5"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72656.json","vanir_signatures_modified":"2026-09-06T08:14:58Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}