Bug 2547116 (CVE-2026-103005) - CVE-2026-103005 elasticsearch: Elasticsearch: Denial of Service via excessive memory allocation in connector descriptions
Summary: CVE-2026-103005 elasticsearch: Elasticsearch: Denial of Service via excessive...
Keywords:
Status: NEW
Alias: CVE-2026-103005
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2547810 2547811 2547812
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 19:54 UTC by OSIDB Bzimport
Modified: 2026-10-08 07:35 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 19:54:33 UTC
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.


Note You need to log in before you can comment on or make changes to this bug.