THREAT OPS › Threat News › [NVD] CVE-2026-72656 (MEDIUM 6.5) — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation alloca
[NVD] CVE-2026-72656 (MEDIUM 6.5) — Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation alloca
CVE-2026-72656 CVSS: 6.5 MEDIUM Published: 2026-08-13T20:17:25.747
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory, exhausting t
Indicators of compromise
- CVE-2026-72656cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72656