We found results for “”
CVE-2025-68384
Good to know:
Date: December 18, 2025
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Allocation of Resources Without Limits or Throttling
CWE-770Top Fix
Upgrade Version
Upgrade to version org.elasticsearch.plugin:x-pack-security:9.2.3;org.elasticsearch.plugin:x-pack-security:9.1.9;org.elasticsearch.plugin:x-pack-security:8.19.9;https://github.com/elastic/elasticsearch.git - v9.2.3;https://github.com/elastic/elasticsearch.git - v9.1.9;https://github.com/elastic/elasticsearch.git - v8.19.9
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


