Elasticsearch security advisories
43 advisories · none critical or high in 12 months · latest Dec 15, 2025
43 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 152025 | Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates CVE-2025-37731Medium6.8fixed in 8.19.8, 9.1.8, 9.2.2 | Medium6.8 | 8.19.8, 9.1.8, 9.2.2 |
| Oct 102025 | Elasticsearch: Insertion of Sensitive Information into Log File via reindex API CVE-2025-37727Medium5.7fixed in 8.18.8, 8.19.5, 9.0.8, 9.1.5 | Medium5.7 | 8.18.8, 8.19.5, 9.0.8, 9.1.5 |
| May 12025 | Elasticsearch Uncontrolled Resource Consumption Vulnerability CVE-2024-52979Medium6.5fixed in 7.17.25, 8.16.0 | Medium6.5 | 7.17.25, 8.16.0 |
| Apr 82025 | Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion CVE-2024-52981Medium4.9fixed in 7.17.24, 8.15.1 | Medium4.9 | 7.17.24, 8.15.1 |
| Apr 82025 | Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function CVE-2024-52980Medium6.5fixed in 8.15.1 | Medium6.5 | 8.15.1 |
| Jan 212025 | Elasticsearch allocation of resources without limits or throttling leads to crash CVE-2024-43709Medium6.5fixed in 7.17.21, 8.13.3 | Medium6.5 | 7.17.21, 8.13.3 |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-12539Mediumfixed in 8.16.2 | Medium | 8.16.2 |
| Jul 312024 | Elasticsearch stores private key on disk unencrypted CVE-2024-23444Medium4.9fixed in 7.17.23, 8.13.0 | Medium4.9 | 7.17.23, 8.13.0 |
| Jul 262024 | Elasticsearch Insertion of Sensitive Information into Log File CVE-2023-49921Medium5.2fixed in 7.17.16, 8.11.2 | Medium5.2 | 7.17.16, 8.11.2 |
| Jun 132024 | Elasticsearch StackOverflow vulnerability CVE-2024-37280Medium4.9fixed in 8.14.0 | Medium4.9 | 8.14.0 |
| Mar 292024 | Elasticsearch Uncaught Exception leading to crash CVE-2024-23449Medium4.3fixed in 8.11.1 | Medium4.3 | 8.11.1 |
| Mar 272024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-23451Medium4.4fixed in 8.13.0 | Medium4.4 | 8.13.0 |
| Mar 272024 | Elasticsearch Uncontrolled Resource Consumption vulnerability CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0 | Medium4.9 | 7.17.19, 8.13.0 |
| Nov 222023 | Elasticsearch Improper Handling of Exceptional Conditions CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3 | Medium6.5 | 7.17.14, 8.10.3 |
| Oct 262023 | Elasticsearch vulnerable to Uncontrolled Resource Consumption CVE-2023-31418High7.5fixed in 7.17.13, 8.9.0 | High7.5 | 7.17.13, 8.9.0 |
| Oct 262023 | Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2 | Medium4.1 | 7.17.13, 8.9.2 |
| Oct 262023 | Elasticsearch vulnerable to stack overflow in the search API CVE-2023-31419Medium6.5fixed in 7.17.13, 8.9.1 | Medium6.5 | 7.17.13, 8.9.1 |
| Jun 72022 | Improper Check for Unusual or Exceptional Conditions in Elasticsearch CVE-2022-23712High7.5fixed in 8.2.1 | High7.5 | 8.2.1 |
| May 242022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2021-22137Medium5.3fixed in 6.8.15, 7.11.2 | Medium5.3 | 6.8.15, 7.11.2 |
| May 242022 | Insertion of Sensitive Information into Log File in Elasticsearch CVE-2020-7021Medium4.9fixed in 6.8.14, 7.10.0 | Medium4.9 | 6.8.14, 7.10.0 |
| May 242022 | Improper privilege management in elasticsearch CVE-2020-7019Medium6.5fixed in 6.8.12, 7.9.0 | Medium6.5 | 6.8.12, 7.9.0 |
| May 242022 | Improper Privilege Management in Elasticsearch CVE-2020-7009High8.8fixed in 6.8.8, 7.6.2 | High8.8 | 6.8.8, 7.6.2 |
| May 242022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2019-7619Medium5.3fixed in 6.8.4, 7.4.0 | Medium5.3 | 6.8.4, 7.4.0 |
| May 242022 | Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch CVE-2019-7614Medium5.9fixed in 6.8.2, 7.2.1 | Medium5.9 | 6.8.2, 7.2.1 |
| May 172022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch CVE-2015-3337Mediumfixed in 1.4.5, 1.5.2 | Medium | 1.4.5, 1.5.2 |
| May 172022 | Elasticsearch Improper Access Control vulnerability CVE-2014-3120High8.1fixed in 1.4.0.Beta1 | High8.1 | 1.4.0.Beta1 |
| May 142022 | Cross-site scripting in Elasticsearch CVE-2014-6439Mediumfixed in 1.4.0.Beta1 | Medium | 1.4.0.Beta1 |
| May 142022 | Improper Access Control in Elasticsearch CVE-2015-1427Highfixed in 1.3.8, 1.4.3 | High | 1.3.8, 1.4.3 |
| May 142022 | Improper Access Control in Elasticsearch CVE-2015-4165High7.5fixed in 1.6.0 | High7.5 | 1.6.0 |
| May 142022 | Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch CVE-2015-5531Mediumfixed in 1.6.1 | Medium | 1.6.1 |
| May 132022 | Improper Restriction of XML External Entity Reference in Elasticsearch CVE-2018-17247Medium5.9fixed in 6.5.2 | Medium5.9 | 6.5.2 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2018-17244Medium6.5fixed in 6.4.3 | Medium6.5 | 6.4.3 |
| May 132022 | Elasticsearch subject to cross site scripting CVE-2018-3824Medium6.1fixed in 5.6.9, 6.2.4 | Medium6.1 | 5.6.9, 6.2.4 |
| May 132022 | Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch CVE-2018-3831High8.8fixed in 5.6.12, 6.4.1 | High8.8 | 5.6.12, 6.4.1 |
| May 132022 | Improper Access Control in Elasticsearch CVE-2019-7611High8.1fixed in 5.6.15, 6.6.1 | High8.1 | 5.6.15, 6.6.1 |
| Mar 42022 | Elasticsearch privilege escalation CVE-2022-23708Medium4.3fixed in 7.17.1 | Medium4.3 | 7.17.1 |
| Sep 202021 | Exposure of sensitive information in Elasticsearch CVE-2021-22147Medium6.5fixed in 7.14.0 | Medium6.5 | 7.14.0 |
| Aug 92021 | Denial of Service in Elasticsearch CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3 | Medium5.7 | 6.8.17, 7.13.3 |
| Jul 22021 | API information disclosure flaw in Elasticsearch CVE-2021-22135Medium5.3fixed in 6.8.15, 7.11.2 | Medium5.3 | 6.8.15, 7.11.2 |
| Mar 182021 | Insufficiently Protected Credentials in Elasticsearch CVE-2021-22132Medium4.8fixed in 7.10.2 | Medium4.8 | 7.10.2 |
| Mar 182021 | Privilege Escalation Flaw in Elasticsearch CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2 | Medium8.8 | 6.8.8, 7.6.2 |
| Mar 182021 | Privilege Context Switching Error in Elasticsearch CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2 | Low3.1 | 6.8.13, 7.9.2 |
| Mar 182021 | Exposure of Sensitive Information to an Unauthorized Actor CVE-2021-22134Medium4.3fixed in 7.11.0 | Medium4.3 | 7.11.0 |
About Elasticsearch
The search and analytics engine.
Packages watched: org.elasticsearch:elasticsearch (Maven).
Elastic elsewhere on fru.dev: Acquisitions · Quarterly · Paydays · Releases · Repos · TechConf