Skip to main content

Vendor archive

elasticsearch CVEs

Beta · best-effort

19 CVEs tagged to vendor elasticsearch0 Critical, 4 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2026-26933

Published Mar 19, 2026

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker w…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26932

Published Feb 26, 2026

Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can se…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68388

Published Dec 18, 2025

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68382

Published Dec 18, 2025

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68381

Published Dec 18, 2025

Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause sign…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11480

Published Dec 8, 2017

Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is abl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8444

Published Sep 29, 2017

The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traff…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11479

Published Sep 29, 2017

Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14730

Published Sep 25, 2017

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5619

Published Aug 9, 2017

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might al…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4165

Published Aug 9, 2017

The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5531

Published Aug 17, 2015

Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-3337

Published May 1, 2015

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6439

Published Oct 10, 2014

Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1