Skip to content
ElasticsearchGHSA-5xm9-x7x4-4j5x

Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion

Medium4.9CVE-2024-52981 · Published Apr 8, 2025 · updated May 27, 2025

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.17.0, < 7.17.247.17.24
>= 8.0.0-alpha1, < 8.15.18.15.1
Details and references

More Elasticsearch advisories

All Elasticsearch
Advisory
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Medium5.7Oct 10, 2025
Elasticsearch Uncontrolled Resource Consumption Vulnerability
Medium6.5May 1, 2025
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Medium6.5Apr 8, 2025
Elasticsearch allocation of resources without limits or throttling leads to crash
Medium6.5Jan 21, 2025
Elasticsearch Incorrect Authorization vulnerability
MediumDec 17, 2024
Elasticsearch stores private key on disk unencrypted
Medium4.9Jul 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.