Elasticsearch 中存在非受控递归漏洞(CWE-674),攻击者可利用特制的请求导致拒绝服务(DoS)。该漏洞源于 Elasticsearch 在构建和序列化由脚本运行时字段生成的几何值时,对递归深度缺乏有效限制。 与作为文本提供的几何数据(其嵌套深度受到限制)不同,由脚本输出构建的几何数据未设置任何递归深度上限。具有读取单个索引权限的认证用户,可以提交一个定义此类字段的请求,并使用脚本生成深度嵌套的数据结构。处理该请求时,系统会因递归过深而耗尽可用栈空间,从而导致受影响的节点崩溃。在某些部署环境中,节点
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Elastic | Elasticsearch | 8.12.0≤ 8.19.22 |
affected |
9.0.0≤ 9.4.7 |
affected | ||
9.5.0≤ 9.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Elastic | Elasticsearch | 8.12.0 ~ 8.19.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102406 | 8.8 HIGH | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data In |
| CVE-2026-103007 | 7.2 HIGH | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation |
| CVE-2026-103009 | 7.1 HIGH | Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information D |
| CVE-2026-102412 | 6.5 MEDIUM | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-102409 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102411 | 6.5 MEDIUM | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of |
| CVE-2026-102404 | 6.5 MEDIUM | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-103005 | 6.5 MEDIUM | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service |
| CVE-2026-103006 | 6.5 MEDIUM | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102413 | 6.2 MEDIUM | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-102407 | 5.4 MEDIUM | Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification |
| CVE-2026-102410 | 4.3 MEDIUM | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-102408 | 4.3 MEDIUM | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service |
No comments yet