Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-68384

Elasticsearch: low-privileged user can crash a node with oversized user settings

Technology

Elasticsearch

CVSS Score

6.5 / 10.0

Affected Versions

All 7.x; 8.0.0 to 8.19.8; 9.0.0 to 9.1.8; 9.2.0 to 9.2.2

Upstream Fix

8.19.9; 9.1.9; 9.2.3

Published

December 18, 2025

OSSeva Coverage

Fixed upstream

Description

Allocation of resources without limits in Elasticsearch lets a low-privileged authenticated user submit oversized user settings data and cause a persistent denial of service through an out-of-memory crash. CVSS is Elastic's score as the CNA.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running All 7.x; 8.0.0 to 8.19.8; 9.0.0 to 9.1.8; 9.2.0 to 9.2.2, you need this patch. Book a discovery call to get covered.