← Vulnerability feed

Vulnerability record · CVE-2023-31419 · published 26 October 2023

CVE-2023-31419: Elasticsearch _search API query string stack overflow DoS

Elastic · Elasticsearch

Elasticsearch's _search API fails to safely handle a specially crafted query string, causing a stack overflow that crashes the node. Because the search endpoint is central to normal cluster operation, a single malformed request can take down availability for the whole service.

7.5 CVSS 3.1 High EPSS 62% · top 0.9% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated denial of service with a very high EPSS score, though no confirmed in-the-wild exploitation is documented.

What it is

Elasticsearch's _search API fails to safely handle a specially crafted query string, causing a stack overflow that crashes the node. Because the search endpoint is central to normal cluster operation, a single malformed request can take down availability for the whole service.

Impact

An attacker can crash Elasticsearch nodes, causing denial of service and loss of search and indexing availability. There is no confidentiality or integrity impact per the CVSS vector.

Attack surface

Reachable over the network via the _search API; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required, so any client that can reach the endpoint can attempt it.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.60679 (99.1st percentile), indicating a high predicted likelihood of exploitation activity.

What to do

  • Upgrade to the fixed Elasticsearch release referenced in the vendor advisory (8.9.1 / 7.17.13 security update).
  • Restrict network access to the _search API to trusted clients and place it behind authentication and a reverse proxy.
  • Apply request size and query complexity limits at the proxy or gateway to reject oversized or deeply nested query strings.
  • Monitor Elasticsearch nodes for unexpected restarts or JVM crashes and alert on them.
  • If patching is delayed, isolate affected clusters from untrusted networks.

Detection

  • Alert on Elasticsearch node restarts, JVM crashes, or stack overflow errors in logs.
  • Inspect HTTP access logs for unusually long or deeply nested query strings hitting _search.
  • Baseline normal _search request sizes and flag outliers from unexpected source IPs.
  • Correlate spikes in failed or malformed search requests with availability drops.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-31419 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-1427Elasticsearch Groovy scripting engine sandbox escape RCEThe Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbit…KEVEPSS 100%analysed8.1CVE-2014-3120Elasticsearch dynamic scripting allows remote code executionThe default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expres…KEVEPSS 89%analysed9.8CVE-2015-5377Elasticsearch injection vulnerabilityElasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appe…EPSS 14%8.8CVE-2026-72649Elasticsearch deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (C…EPSS 0.92%8.8CVE-2026-72642Elasticsearch vulnerabilityThe native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory ad…EPSS 0.60%8.8CVE-2021-37937Elasticsearch improper privilege management vulnerabilityAn issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is poss…EPSS 0.71%8.8CVE-2020-7014Elasticsearch improper privilege management vulnerabilityThe fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl…EPSS 1.5%8.8CVE-2020-7009Elasticsearch improper privilege management vulnerabilityElasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-31419), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.