SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-63263

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

Elasticsearch is vulnerable to a denial-of-service attack due to uncontrolled resource consumption, where an authenticated user can submit a crafted query that leads to exponential CPU usage during evaluation. This resource exhaustion can persist beyond the query's completion, potentially rendering ES|QL queries unavailable until the affected node is restarted. Organizations utilizing Elasticsearch, particularly those with user-generated queries, should prioritize addressing this vulnerability to maintain service availability.

CVE
CVE-2026-63263
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource exhaustion persists beyond query completion, repeated requests can fully exhaust the available query worker resources, rendering ES|QL queries unavailable until the node is restarted.

Related CVEs

Other vulnerabilities affecting the same vendor(s)