What is CVE-2026-63136?
An uncontrolled resource consumption vulnerability (CWE-400) has been identified in Elasticsearch. A user with search privileges can submit a specially crafted request that exhausts heap memory on a data node, leading to denial of service (DoS). Applying Elasticsearch updates is recommended to mitigate this issue.
Azərbaycanca: Elasticsearch-də nəzarətsiz resurs istehlakı (CWE-400) zəifliyi aşkar edilib. Axtarış imtiyazları olan istifadəçi, xüsusi hazırlanmış sorğu ilə data node-da heap yaddaşını tükədərək xidmət dayanmasına (DoS) səbəb ola bilər. Bu problemi aradan qaldırmaq üçün Elasticsearch yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Elasticsearch
FAQ2
What level of access does an attacker need to exploit CVE-2026-63136?
The attacker only needs to have search privileges in Elasticsearch.
What is the potential impact of successfully exploiting CVE-2026-63136?
It can lead to a denial of service (DoS) by exhausting heap memory on a data node.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.