CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2023-31419: Elasticsearch StackOverflow vulnerability

mediumCVSS 6.5CVE-2023-31419

CSIRTS triage

What
Stack overflow vulnerability in Elasticsearch allows attacker to exhaust stack memory and crash process.
Who is affected
Elasticsearch deployments accepting untrusted input that triggers deep recursion or nesting.
Urgency
Medium severity (CVSS 6.5); denial of service impact requires specific input conditions but can crash clusters.
Action
Update Elasticsearch to version containing stack overflow mitigation.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Elasticsearch

Get an email when a new Elasticsearch advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 6.5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-31419

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2023-31419coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center