{"id":"GHSA-ghfh-p92w-j4mg","summary":"Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function","details":"A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash.\n\nA successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.","aliases":["BIT-elasticsearch-2024-52980","CVE-2024-52980"],"modified":"2026-09-25T17:45:04.835167390Z","published":"2025-04-08T18:34:42Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-09T13:02:50Z","nvd_published_at":"2025-04-08T17:15:34Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52980"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/commit/4e5c6801f4d60f100f122072f6bf35b21fd722a5"},{"type":"WEB","url":"https://github.com/elastic/elasticsearch/commit/a02dc7165c75f12701f8d47a2bdefe5283735267"},{"type":"WEB","url":"https://discuss.elastic.co/t/elasticsearch-8-15-1-security-update-esa-2024-34/376919"},{"type":"PACKAGE","url":"https://github.com/elastic/elasticsearch"}],"affected":[{"package":{"name":"org.elasticsearch:elasticsearch-grok","ecosystem":"Maven","purl":"pkg:maven/org.elasticsearch/elasticsearch-grok"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.17.0"},{"fixed":"8.15.1"}]}],"versions":["8.10.0","8.10.1","8.10.2","8.10.3","8.10.4","8.11.0","8.11.1","8.11.2","8.11.3","8.11.4","8.12.0","8.12.1","8.12.2","8.13.0","8.13.1","8.13.2","8.13.3","8.13.4","8.14.0","8.14.1","8.14.2","8.14.3","8.15.0","8.5.0","8.5.1","8.5.2","8.5.3","8.6.0","8.6.1","8.6.2","8.7.0","8.7.1","8.8.0","8.8.1","8.8.2","8.9.0","8.9.1","8.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-ghfh-p92w-j4mg/GHSA-ghfh-p92w-j4mg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}