Security Advisory

CVE-2025-68390

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-18 22:17:41
Last updated 2025-12-19 15:36:02
Assigner elastic
State PUBLISHED

Description

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.