6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Description
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.
Basic Information
ID
CVE-2025-68384
Source
elastic
Published
Dec 18, 2025 at 22:04
Affected Product
Vendor
Elastic
Product
Elasticsearch
Version
7.0.0
Affected Versions
Elastic Elasticsearch 7.0.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.2.0
Elastic Elasticsearch 8.0.0
Elastic Elasticsearch 9.0.0
Elastic Elasticsearch 9.2.0