MEDIUMVulnerability

CVE-2026-72645

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted search request that causes an excessively large memory allocation, exhausting the JVM heap and terminating the affected node.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00296
cve_id
CVE-2026-72645
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-13T20:17:24.927
last_modified
2026-09-01T15:31:26.297
epss_percentile
0.21798

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72645 — Ninja Signal Threat Intelligence | Ninja Signal