EIQ-2026-0008#
ID |
EIQ-2026-0008 |
|---|---|
CVE |
CVE-2026-63144 |
Description |
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
Date |
30 July 2026 |
Severity |
2 - MEDIUM |
CVSSv3 score |
6.5 |
Status |
⏲ |
Assessment |
Uncontrolled Recursion in Elasticsearch. A specially crafted search request with deeply nested parentheses in a query_string query can drive Lucene’s query parser into deep recursion until the JVM stack overflows. The resulting fatal error terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate. To trigger this exploit, the attacker would need to be authenticated as a user of the EclecticIQ Intelligence Center, or have compromised access to Elasticsearch users. On EclecticIQ Intelligence Center, a user with Links: |
Mitigation |
Upgrade to IC 3.8.0 when available, which ships with Elasticsearch 9.4.4. |
Affected versions |
EIQ Intelligence Center 3.7.2 and older, or any instance using Elasticsearch versions 8.x from 8.19.0 up to 8.19.18 (inclusive), 9.x from 9.3.0 up to 9.3.7 (inclusive), 9.4.x up to 9.4.3 (inclusive). |
Notes |
N/A |