CVE-2026-56149: Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a sp...
Added to the CISA Known Exploited Vulnerabilities catalog on 01 Jul 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 4.9.
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render ...
Required action: Review and patch if applicable to your AI infrastructure.