ElasticsearchGHSA-5xm9-x7x4-4j5x
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
Medium4.9CVE-2024-52981 · Published Apr 8, 2025 · updated May 27, 2025
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.17.0, < 7.17.24 | 7.17.24 |
| >= 8.0.0-alpha1, < 8.15.1 | 8.15.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- BIT-elasticsearch-2024-52981, CVE-2024-52981
- nvd.nist.gov/vuln/detail/CVE-2024-52981
- github.com/elastic/elasticsearch/commit/097fc0654f9305e01402a06c82926bb04ebe5495
- github.com/elastic/elasticsearch/commit/91ddb124219a5be992644fcf78d7d061e4b7d44c
- github.com/elastic/elasticsearch/commit/f0948d38fdc811eca4a4b71dcb81a9b7dbb654b3
- discuss.elastic.co/t/elasticsearch-7-17-24-and-8-15-1-security-update-esa-2024-37/376924
- github.com/elastic/elasticsearch
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 102025 | Elasticsearch: Insertion of Sensitive Information into Log File via reindex API | Medium5.7 | 8.18.8+3 more |
| May 12025 | Elasticsearch Uncontrolled Resource Consumption Vulnerability | Medium6.5 | 7.17.25+1 more |
| Apr 82025 | Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function | Medium6.5 | 8.15.1 |
| Jan 212025 | Elasticsearch allocation of resources without limits or throttling leads to crash | Medium6.5 | 7.17.21+1 more |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability | Medium | 8.16.2 |
| Jul 312024 | Elasticsearch stores private key on disk unencrypted | Medium4.9 | 7.17.23+1 more |