云虫漏洞情报

CVE-2026-72679 - Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request. - 漏洞详情

漏洞编号:CVE-2026-72679

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-72679

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-674

发布/更新时间:2026-08-13 / 2026-08-28

漏洞描述

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.

相关链接

相关漏洞

« 返回首页