PT-2025-52370 · Elastic · Elasticsearch

Ismisepaul

+1

·

Published

2025-12-18

·

Updated

2026-04-28

·

CVE-2025-68390

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Elasticsearch (affected versions not specified)
Description An issue exists in Elasticsearch where an authenticated user with snapshot restore privileges can cause excessive memory allocation, leading to a denial of service. This occurs through crafted HTTP requests. The issue is related to the allocation of resources without limits or throttling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BIT-ELASTICSEARCH-2025-68390
CVE-2025-68390
GHSA-GPHJ-4H6P-37XQ

Affected Products

Elasticsearch