Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch query evaluation component, causing a fatal error that terminates the affected node. In single-node deployments, this results in complete service outage; in multi-node clusters, it causes repeated node restarts and sustained availability degradation.
References
| Link | Resource |
|---|---|
| https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-68/388571 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Aug 2026, 16:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-68/388571 - Vendor Advisory | |
| First Time |
Elastic elasticsearch
Elastic |
|
| CPE | cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:* |
21 Jul 2026, 23:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-21 23:18
Updated : 2026-08-03 16:07
NVD link : CVE-2026-63144
Mitre link : CVE-2026-63144
CVE.ORG link : CVE-2026-63144
JSON object : View
Products Affected
elastic
- elasticsearch
CWE
CWE-674
Uncontrolled Recursion
