Elasticsearch
This hub aggregates every CVE we track for Elasticsearch, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
59
CVEs tracked
2
Critical
12
High
2
In CISA KEV
Severity distribution
MEDIUM43HIGH12LOW2CRITICAL2
Monthly trend
2
0
0
0
0
1
1
0
0
2
2
0
0
0
0
1
0
3
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Elasticsearch.
- CVE-2025-68390Elasticsearch Allocation of Resources Without Limits or Throttling4.9
- CVE-2025-68384Elasticsearch Allocation of Resources Without Limits or Throttling6.5
- CVE-2025-37731Elasticsearch Improper Authentication6.8
- CVE-2025-37727Elasticsearch Insertion of sensitive information in log file5.7
- BDU:2025-05749Уязвимость поисковой системы ElasticSearch, связанная с недостаточным ограничением попыток аутентификации, позволяющая нарушителю реализовать атаку методом "грубой силы" (brute force) и повысить свои привилегии8.1
- CVE-2024-52979Elasticsearch Uncontrolled Resource Consumption vulnerability6.5
- CVE-2024-52981An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.4.9
- CVE-2024-52980Elasticsearch Uncontrolled Resource Consumption vulnerability6.5
- CVE-2024-43709Elasticsearch allocation of resources without limits or throttling leads to crash6.5
- CVE-2024-12539Elasticsearch Incorrect Authorization6.5
- CVE-2024-23444Elasticsearch elasticsearch-certutil csr fails to encrypt private key4.9
- CVE-2023-49921An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printe...5.2
- CVE-2024-37280Elasticsearch StackOverflow vulnerability4.9
- CVE-2024-23445Elasticsearch Remote Cluster Search Cross Cluster API Key insufficient restrictions6.5
- CVE-2024-23449Elasticsearch Uncaught Exception4.3
Product normalization is registry-driven with AI assist and human review. How it works