THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-72656 (MEDIUM 6.5) — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation alloca

[NVD] CVE-2026-72656 (MEDIUM 6.5) — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation alloca

mednvdPublished 2026-08-13

CVE-2026-72656 CVSS: 6.5 MEDIUM Published: 2026-08-13T20:17:25.747

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72656