CVE-2026-72678
CVE-2026-72678: 2 tracked advisory records across NetApp, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
NetApp
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-72678] Elasticsearch Vulnerability in NetApp Products
NTAP-20261009-0008Source published Source updated
Elasticsearch versions 8.19.0 through 8.19.0, 9.4.0 through 9.4.4 and 9.5.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 8.19.0
- 9.4.0
- 9.4.4
- 9.5.0
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-72678] Denial of Service via excessive memory allocation
CVE-2026-72678Source published Source updated
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that causes the node to attempt an excessively large allocation. The resulting memory exhaustion raises a fatal error that terminates the Elasticsearch node process, causing a denial of service for the affected node and degrading cluster health. The defect is not volumetric, so a single request is sufficient regardless of the heap size configured on the target node. A flaw was found in Elasticsearch. An unvalidated allocation flaw exists in Elasticsearch's API request processing mechanisms. When handling user-supplied…
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- Restrict API access permissions using Elasticsearch role-based access control (RBAC) so that only trusted users can access read endpoints. Additionally, configure request circuit breakers (`indices.breaker.request.limit`) to enforce strict memory allocation caps per request execution.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.