
CVE advisory: CVE-2026-72636 - netapp: CVE-2026-72636 Elasticsearch Vulnerability in NetApp Products. https://vulnipulse.com/advisories/netapp-ntap-20261009-0002 #CVE #CyberSecurity #NetApp #Elasticsearch
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on the total number of match operations performed. A search request containing a wildcard pattern with a large number of wildcard groups, evaluated against a sufficiently long name, exhausts the thread stack. Elasticsearch treats a stack overflow as an unrecoverable condition and shuts the node down, so the request terminates the affected node rather than failing gracefully.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

CVE advisory: CVE-2026-72636 - netapp: CVE-2026-72636 Elasticsearch Vulnerability in NetApp Products. https://vulnipulse.com/advisories/netapp-ntap-20261009-0002 #CVE #CyberSecurity #NetApp #Elasticsearch
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | elastic | elasticsearch | - | - | - |