Vulnerability record · CVE-2023-31419 · published 26 October 2023
CVE-2023-31419: Elasticsearch _search API query string stack overflow DoS
Elastic · Elasticsearch
Elasticsearch's _search API fails to safely handle a specially crafted query string, causing a stack overflow that crashes the node. Because the search endpoint is central to normal cluster operation, a single malformed request can take down availability for the whole service.
Description
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityNetwork-reachable, unauthenticated denial of service with a very high EPSS score, though no confirmed in-the-wild exploitation is documented.
What it is
Elasticsearch's _search API fails to safely handle a specially crafted query string, causing a stack overflow that crashes the node. Because the search endpoint is central to normal cluster operation, a single malformed request can take down availability for the whole service.
Impact
An attacker can crash Elasticsearch nodes, causing denial of service and loss of search and indexing availability. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network via the _search API; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required, so any client that can reach the endpoint can attempt it.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.60679 (99.1st percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Upgrade to the fixed Elasticsearch release referenced in the vendor advisory (8.9.1 / 7.17.13 security update).
- Restrict network access to the _search API to trusted clients and place it behind authentication and a reverse proxy.
- Apply request size and query complexity limits at the proxy or gateway to reject oversized or deeply nested query strings.
- Monitor Elasticsearch nodes for unexpected restarts or JVM crashes and alert on them.
- If patching is delayed, isolate affected clusters from untrusted networks.
Detection
- Alert on Elasticsearch node restarts, JVM crashes, or stack overflow errors in logs.
- Inspect HTTP access logs for unusually long or deeply nested query strings hitting _search.
- Baseline normal _search request sizes and flag outliers from unexpected source IPs.
- Correlate spikes in failed or malformed search requests with availability drops.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://discuss.elastic.co/t/elasticsearch-8-9-1-7-17-13-security-update/343297 | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20231116-0010/ | Third Party Advisory |
| https://www.elastic.co/community/security | Vendor Advisory |
| https://discuss.elastic.co/t/elasticsearch-8-9-1-7-17-13-security-update/343297 | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20231116-0010/ | Third Party Advisory |
| https://www.elastic.co/community/security | Vendor Advisory |
Track CVE-2023-31419 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-31419), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.