Bug 2547125 (CVE-2026-103006) - CVE-2026-103006 elasticsearch: Elasticsearch: Denial of Service via deeply nested search aggregations
Summary: CVE-2026-103006 elasticsearch: Elasticsearch: Denial of Service via deeply ne...
Keywords:
Status: NEW
Alias: CVE-2026-103006
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-06 19:55 UTC by OSIDB Bzimport
Modified: 2026-10-06 20:51 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-06 19:55:52 UTC
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access to a single index can submit a specially crafted request containing deeply nested aggregation definitions. Processing this request triggers unbounded recursive execution that exhausts the server process's available resources, causing the affected node to terminate. The node does not recover automatically and requires manual intervention to restore service.


Note You need to log in before you can comment on or make changes to this bug.