VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-56149

CVE-2026-56149: Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce

Published Jul 1, 2026 CVSS 4.9

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

Affected AI Products

machine learning
Get the weekly digest. Every Monday: top AI security stories of the week. Free.