Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63136

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and cluster degradation. An attacker could leverage this vulnerability to cause cluster downtime requiring manual intervention to restore service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 15.4%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-63136


Contact Us

Shodan ® - All rights reserved