Skip to content
ElasticsearchGHSA-4q22-422g-m4pj

Elasticsearch StackOverflow vulnerability

Medium4.9CVE-2024-37280 · Published Jun 13, 2024 · updated Sep 10, 2026

A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 8.13.1, < 8.14.08.14.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-122, CWE-787
Also known as
BIT-elasticsearch-2024-37280, CVE-2024-37280

More Elasticsearch advisories

All Elasticsearch
Advisory
Elasticsearch Incorrect Authorization vulnerability
MediumDec 17, 2024
Elasticsearch stores private key on disk unencrypted
Medium4.9Jul 31, 2024
Elasticsearch Insertion of Sensitive Information into Log File
Medium5.2Jul 26, 2024
Elasticsearch Uncaught Exception leading to crash
Medium4.3Mar 29, 2024
Elasticsearch Incorrect Authorization vulnerability
Medium4.4Mar 27, 2024
Elasticsearch Uncontrolled Resource Consumption vulnerability
Medium4.9Mar 27, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.