Skip to main content

Vendor/product archive

elastic / elasticsearch CVEs

Beta · best-effort

50 CVEs tagged to elastic / elasticsearch2 Critical, 8 High, 39 Medium, 1 Low, 0 Unrated.

CVE-2026-49090

Published Jul 1, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially cra…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56149

Published Jul 1, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileg…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56148

Published Jul 1, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68390

Published Dec 18, 2025

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAP…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68384

Published Dec 18, 2025

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37731

Published Dec 15, 2025

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted cl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-37727

Published Oct 10, 2025

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https:/…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52979

Published May 1, 2025

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elas…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52981

Published Apr 8, 2025

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52980

Published Apr 8, 2025

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to cra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43709

Published Jan 21, 2025

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a specially crafted query using an SQL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12539

Published Dec 17, 2024

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch an…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23444

Published Jul 31, 2024

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associate…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49921

Published Jul 26, 2024

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elastics…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37280

Published Jun 13, 2024

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, in…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23445

Published Jun 12, 2024

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23449

Published Mar 29, 2024

An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. The Elasticsearch ingest node…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23451

Published Mar 27, 2024

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23450

Published Mar 27, 2024

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46674

Published Dec 5, 2023

An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users.…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46673

Published Nov 22, 2023

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37937

Published Nov 22, 2023

An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31419

Published Oct 26, 2023

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31417

Published Oct 26, 2023

Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasti…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2