
CVE advisory: CVE-2026-72679 - netapp: CVE-2026-72679 Elasticsearch Vulnerability in NetApp Products. https://vulnipulse.com/advisories/netapp-ntap-20261009-0009 #CVE #CyberSecurity #NetApp #Elasticsearch
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

CVE advisory: CVE-2026-72679 - netapp: CVE-2026-72679 Elasticsearch Vulnerability in NetApp Products. https://vulnipulse.com/advisories/netapp-ntap-20261009-0009 #CVE #CyberSecurity #NetApp #Elasticsearch
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | elastic | elasticsearch | - | - | - |