4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.
Basic Information
ID
CVE-2025-68390
Source
elastic
Published
Dec 18, 2025 at 22:17
Affected Product
Vendor
Elastic
Product
Elasticsearch
Version
7.0.0
Affected Versions
Elastic Elasticsearch 7.0.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.2.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.2.0