VendorsElasticelasticsearchall versions
Vulnerabilities

Elastic Elasticsearch

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

74CVEs
CVE-2026-49090
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2026-63263
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2026-63144
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2026-63140
Reachable Assertion in Elasticsearch Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2026-63136
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2026-72687
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72684
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72638
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72656
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72639
Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72645
Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72647
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2026-72636
Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service
Published 2026-08-13 · Analyzed
6.5EPSS 0.004
CVE-2025-68384
Elasticsearch Allocation of Resources Without Limits or Throttling
Published 2025-12-18 · Analyzed
6.5EPSS 0.003
CVE-2026-56144
Incorrect Authorization in Elasticsearch Leading to Information Disclosure
Published 2026-07-21 · Analyzed
6.5EPSS 0.003
CVE-2018-17247
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.
Published 2018-12-20 · Modified
5.9EPSS 0.014
CVE-2019-7614
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.
Published 2019-07-30 · Modified
5.9EPSS 0.010
CVE-2026-78605
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure
Published 2026-09-01 · Analyzed
5.9EPSS 0.003
CVE-2025-37727
Elasticsearch Insertion of sensitive information in log file
Published 2025-10-10 · Analyzed
5.7EPSS 0.002
CVE-2019-7619
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.
Published 2019-10-30 · Modified
5.3EPSS 0.024
CVE-2021-22135
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.
Published 2021-05-13 · Modified
5.3EPSS 0.012
CVE-2021-22137
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
Published 2021-05-13 · Modified
5.3EPSS 0.011
CVE-2024-23449
Elasticsearch Uncaught Exception
Published 2024-03-29 · Analyzed
5.3EPSS 0.007
CVE-2020-7021
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled. The Elasticsearch audit log could contain sensitive information such as password hashes or authentication tokens. This could allow an Elasticsearch administrator to view these details.
Published 2021-02-10 · Modified
4.9EPSS 0.013
CVE-2024-37280
Elasticsearch StackOverflow vulnerability
Published 2024-06-13 · Modified
4.9EPSS 0.006
CVE-2026-56149
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Published 2026-07-01 · Analyzed
4.9EPSS 0.005
CVE-2026-56143
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
Published 2026-09-01 · Analyzed
4.9EPSS 0.004
CVE-2025-68390
Elasticsearch Allocation of Resources Without Limits or Throttling
Published 2025-12-18 · Analyzed
4.9EPSS 0.004
CVE-2021-22132
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2
Published 2021-01-14 · Modified
4.8EPSS 0.012
CVE-2023-31417
Elasticsearch Insertion of sensitive information in audit logs
Published 2023-10-26 · Modified
4.4EPSS 0.002
CVE-2021-22134
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.
Published 2021-03-08 · Modified
4.3EPSS 0.011
CVE-2022-23708
A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disable the in-built protections on the security index, allowing authenticated users with “*” index permissions access to this index.
Published 2022-03-03 · Modified
4.3EPSS 0.009
CVE-2026-72685
Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service
Published 2026-08-13 · Analyzed
4.3EPSS 0.004
CVE-2020-7020
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.
Published 2020-10-22 · Modified
3.5EPSS 0.010
← Prev2 / 2