OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-103005

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to a denial of service due to excessive memory allocation triggered by authenticated users with connector management privileges. By creating connector resources with overly large `description` fields, these users can exhaust the node's heap memory, potentially leading to crashes. Organizations using Elasticsearch should prioritize addressing this vulnerability to prevent service disruptions.

CVE
CVE-2026-103005
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large `description` field are created and subsequently accessed, exhausting available heap memory and crashing the affected node.

Related CVEs

Other vulnerabilities affecting the same vendor(s)