Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-72683

Elasticsearch: simulate pipeline request causes unbounded recursion and kills the node

Technology

Elasticsearch

CVSS Score

6.5 / 10.0

Affected Versions

5.0.0 to 8.19.18; 9.3.0 to 9.3.7; 9.4.0 to 9.4.3

Upstream Fix

8.19.19; 9.3.8; 9.4.4

Published

August 13, 2026

OSSeva Coverage

Fixed upstream

Description

An authenticated user with the privileges to call the simulate pipeline API can submit a request that creates a self-referential data structure. When an internal component later processes it, the operation recurses without bound and raises a fatal error that terminates the node process. Elastic lists every version from 5.0.0 as affected. CVSS is Elastic's score as the CNA.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running 5.0.0 to 8.19.18; 9.3.0 to 9.3.7; 9.4.0 to 9.4.3, you need this patch. Book a discovery call to get covered.