CVE-2026-72683
Elasticsearch: simulate pipeline request causes unbounded recursion and kills the node
Technology
Elasticsearch
CVSS Score
6.5 / 10.0
Affected Versions
5.0.0 to 8.19.18; 9.3.0 to 9.3.7; 9.4.0 to 9.4.3
Upstream Fix
8.19.19; 9.3.8; 9.4.4
Published
August 13, 2026
OSSeva Coverage
Fixed upstream
Description
An authenticated user with the privileges to call the simulate pipeline API can submit a request that creates a self-referential data structure. When an internal component later processes it, the operation recurses without bound and raises a fatal error that terminates the node process. Elastic lists every version from 5.0.0 as affected. CVSS is Elastic's score as the CNA.
Is your Elasticsearch deployment affected?
If you're running 5.0.0 to 8.19.18; 9.3.0 to 9.3.7; 9.4.0 to 9.4.3, you need this patch. Book a discovery call to get covered.