Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elastic
Elastic elasticsearch |
|
| Vendors & Products |
Elastic
Elastic elasticsearch |
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on the total number of match operations performed. A search request containing a wildcard pattern with a large number of wildcard groups, evaluated against a sufficiently long name, exhausts the thread stack. Elasticsearch treats a stack overflow as an unrecoverable condition and shuts the node down, so the request terminates the affected node rather than failing gracefully. | |
| Title | Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-08-13T20:26:48.047Z
Reserved: 2026-08-10T11:17:29.887Z
Link: CVE-2026-72636
Updated: 2026-08-13T20:26:43.223Z
Status : Received
Published: 2026-08-13T20:17:24.187
Modified: 2026-08-13T21:18:09.160
Link: CVE-2026-72636
No data.
OpenCVE Enrichment
Updated: 2026-08-13T21:00:06Z
-
CWE-674
Uncontrolled Recursion