漏洞概述 漏洞名称: Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service CVE ID: CVE-2026-72656 CWE ID: CWE-789 - Memory Allocation with Excessive Size Value CAPEC ID: CAPEC-130 - Excessive Allocation 严重程度: CVSSv3.1: Medium (6.5) 问题类型: Memory Allocation with Excessive Size Value 影响: CAPEC-130 - Excessive Allocation 影响范围 受影响版本: - 8.x: 从8.11.0到8.17.9的所有版本 - 8.11.0之前的版本不受影响,因为ES/QL查询语言是在8.11.0中引入的 受影响配置: - 所有配置均受影响,ES/QL默认启用 - 利用需要授权运行ES/QL查询的账户 修复方案 解决方案: 该问题在8.18.0和9.0.0版本中已解决 无法升级的用户: 没有针对此漏洞的变通方法 相关主题 Elasticsearch 8.19.20, 9.4.5, 9.5.1 Security Update (ESA-2026-116) Elasticsearch 8.19.20, 9.4.5, 9.5.1 Security Update (ESA-2026-80) Elasticsearch 8.19.20, 9.4.5, 9.5.1 Security Update (ESA-2026-79) Elasticsearch 8.19.20, 9.4.5 Security Update (ESA-2026-76) Elasticsearch 8.19.18, 9.3.7, 9.4.4 Security Update (ESA-2026-57) 页面信息 发布时间: 2024年8月13日 作者: Ioannis Kakavas (Elastic Team Member) 浏览量: 38次 回复数: 0