CVE-2025-68384
MEDIUMElasticsearch < 7.17.29 - Resource Allocation Without Limits
Title source: ruleDescription
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.
Scores
CVSS v3
6.5
EPSS
0.0006
EPSS Percentile
17.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-770
Status
published
Affected Products (2)
elastic/elasticsearch
< 7.17.29
org.elasticsearch.plugin/x-pack-security
< 8.19.9Maven
Timeline
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026