ElasticsearchGHSA-4q22-422g-m4pj
Elasticsearch StackOverflow vulnerability
Medium4.9CVE-2024-37280 · Published Jun 13, 2024 · updated Sep 10, 2026
A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 8.13.1, < 8.14.0 | 8.14.0 |
Details and references
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability | Medium | 8.16.2 |
| Jul 312024 | Elasticsearch stores private key on disk unencrypted | Medium4.9 | 7.17.23+1 more |
| Jul 262024 | Elasticsearch Insertion of Sensitive Information into Log File | Medium5.2 | 7.17.16+1 more |
| Mar 292024 | Elasticsearch Uncaught Exception leading to crash | Medium4.3 | 8.11.1 |
| Mar 272024 | Elasticsearch Incorrect Authorization vulnerability | Medium4.4 | 8.13.0 |
| Mar 272024 | Elasticsearch Uncontrolled Resource Consumption vulnerability | Medium4.9 | 7.17.19+1 more |