Elasticsearch 9.0.x < 9.4.8 / 9.5.x < 9.5.5 DoS (ESA-2026-198)

medium Nessus Plugin ID 363431

Synopsis

The remote host is missing a security update.

Description

The version of Elasticsearch installed on the remote host is 9.0.x prior to 9.4.8, or 9.5.x prior to 9.5.5. It is, therefore, affected by a vulnerability as referenced in the ESA-2026-198 advisory.

- Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes geometry values produced by scripted runtime fields. Unlike geometry supplied as text, which is subject to a nesting-depth limit, geometry constructed from a script's output is not bounded. An authenticated user with read access to a single index can submit a request defining such a field with a script that produces a deeply nested structure. Processing this request recurses past the available stack space, causing the affected node to terminate. The node does not recover automatically on all deployments and may require manual intervention to restore service. (CVE-2026-103008)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Elasticsearch version 9.4.8, or 9.5.5 or later as appropriate for your release branch.

See Also

https://discuss.elastic.co/t/390872

Plugin Details

Severity: Medium

ID: 363431

File Name: elasticsearch_esa_2026_198.nasl

Version: 1.1

Type: Combined

Agent: unix

Family: Misc.

Published: 10/6/2026

Updated: 10/6/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-103008

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:elastic:elasticsearch, cpe:/a:elasticsearch:elasticsearch

Required KB Items: installed_sw/Elasticsearch

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-103008