icon

We found results for “

CVE-2025-68384

Good to know:

icon
icon

Date: December 18, 2025

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

Severity Score

Severity Score

Weakness Type (CWE)

Allocation of Resources Without Limits or Throttling

CWE-770

Top Fix

icon

Upgrade Version

Upgrade to version org.elasticsearch.plugin:x-pack-security:9.2.3;org.elasticsearch.plugin:x-pack-security:9.1.9;org.elasticsearch.plugin:x-pack-security:8.19.9;https://github.com/elastic/elasticsearch.git - v9.2.3;https://github.com/elastic/elasticsearch.git - v9.1.9;https://github.com/elastic/elasticsearch.git - v8.19.9

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us