Bug 2547811 - CVE-2026-103005 python-elasticsearch6: Elasticsearch: Denial of Service via excessive memory allocation in connector descriptions [epel-all]
Summary: CVE-2026-103005 python-elasticsearch6: Elasticsearch: Denial of Service via e...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: python-elasticsearch6
Version: epel10
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Steve Traylen
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["50470cb0-3573-41bf-8f62-9...
Depends On:
Blocks: CVE-2026-103005
TreeView+ depends on / blocked
 
Reported: 2026-10-08 07:34 UTC by Ganesh
Modified: 2026-10-08 07:34 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-10-08 07:34:50 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.


Note You need to log in before you can comment on or make changes to this bug.