Skip to content

Elasticsearch security advisories

43 advisories · none critical or high in 12 months · latest Dec 15, 2025

43 advisories

DateAdvisory
Dec 152025Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2025-37731Medium6.8fixed in 8.19.8, 9.1.8, 9.2.2
Oct 102025Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
CVE-2025-37727Medium5.7fixed in 8.18.8, 8.19.5, 9.0.8, 9.1.5
May 12025Elasticsearch Uncontrolled Resource Consumption Vulnerability
CVE-2024-52979Medium6.5fixed in 7.17.25, 8.16.0
Apr 82025Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
CVE-2024-52981Medium4.9fixed in 7.17.24, 8.15.1
Apr 82025Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2024-52980Medium6.5fixed in 8.15.1
Jan 212025Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2024-43709Medium6.5fixed in 7.17.21, 8.13.3
Dec 172024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-12539Mediumfixed in 8.16.2
Jul 312024Elasticsearch stores private key on disk unencrypted
CVE-2024-23444Medium4.9fixed in 7.17.23, 8.13.0
Jul 262024Elasticsearch Insertion of Sensitive Information into Log File
CVE-2023-49921Medium5.2fixed in 7.17.16, 8.11.2
Jun 132024Elasticsearch StackOverflow vulnerability
CVE-2024-37280Medium4.9fixed in 8.14.0
Mar 292024Elasticsearch Uncaught Exception leading to crash
CVE-2024-23449Medium4.3fixed in 8.11.1
Mar 272024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-23451Medium4.4fixed in 8.13.0
Mar 272024Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23450Medium4.9fixed in 7.17.19, 8.13.0
Nov 222023Elasticsearch Improper Handling of Exceptional Conditions
CVE-2023-46673Medium6.5fixed in 7.17.14, 8.10.3
Oct 262023Elasticsearch vulnerable to Uncontrolled Resource Consumption
CVE-2023-31418High7.5fixed in 7.17.13, 8.9.0
Oct 262023Elasticsearch allows insertion of sensitive information into log files when using deprecated URIs
CVE-2023-31417Medium4.1fixed in 7.17.13, 8.9.2
Oct 262023Elasticsearch vulnerable to stack overflow in the search API
CVE-2023-31419Medium6.5fixed in 7.17.13, 8.9.1
Jun 72022Improper Check for Unusual or Exceptional Conditions in Elasticsearch
CVE-2022-23712High7.5fixed in 8.2.1
May 242022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2021-22137Medium5.3fixed in 6.8.15, 7.11.2
May 242022Insertion of Sensitive Information into Log File in Elasticsearch
CVE-2020-7021Medium4.9fixed in 6.8.14, 7.10.0
May 242022Improper privilege management in elasticsearch
CVE-2020-7019Medium6.5fixed in 6.8.12, 7.9.0
May 242022Improper Privilege Management in Elasticsearch
CVE-2020-7009High8.8fixed in 6.8.8, 7.6.2
May 242022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2019-7619Medium5.3fixed in 6.8.4, 7.4.0
May 242022Concurrent Execution using Shared Resource with Improper Synchronization in Elasticsearch
CVE-2019-7614Medium5.9fixed in 6.8.2, 7.2.1
May 172022Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-3337Mediumfixed in 1.4.5, 1.5.2
May 172022Elasticsearch Improper Access Control vulnerability
CVE-2014-3120High8.1fixed in 1.4.0.Beta1
May 142022Cross-site scripting in Elasticsearch
CVE-2014-6439Mediumfixed in 1.4.0.Beta1
May 142022Improper Access Control in Elasticsearch
CVE-2015-1427Highfixed in 1.3.8, 1.4.3
May 142022Improper Access Control in Elasticsearch
CVE-2015-4165High7.5fixed in 1.6.0
May 142022Improper Limitation of a Pathname to a Restricted Directory in Elasticsearch
CVE-2015-5531Mediumfixed in 1.6.1
May 132022Improper Restriction of XML External Entity Reference in Elasticsearch
CVE-2018-17247Medium5.9fixed in 6.5.2
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2018-17244Medium6.5fixed in 6.4.3
May 132022Elasticsearch subject to cross site scripting
CVE-2018-3824Medium6.1fixed in 5.6.9, 6.2.4
May 132022Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
CVE-2018-3831High8.8fixed in 5.6.12, 6.4.1
May 132022Improper Access Control in Elasticsearch
CVE-2019-7611High8.1fixed in 5.6.15, 6.6.1
Mar 42022Elasticsearch privilege escalation
CVE-2022-23708Medium4.3fixed in 7.17.1
Sep 202021Exposure of sensitive information in Elasticsearch
CVE-2021-22147Medium6.5fixed in 7.14.0
Aug 92021Denial of Service in Elasticsearch
CVE-2021-22144Medium5.7fixed in 6.8.17, 7.13.3
Jul 22021API information disclosure flaw in Elasticsearch
CVE-2021-22135Medium5.3fixed in 6.8.15, 7.11.2
Mar 182021Insufficiently Protected Credentials in Elasticsearch
CVE-2021-22132Medium4.8fixed in 7.10.2
Mar 182021Privilege Escalation Flaw in Elasticsearch
CVE-2020-7014Medium8.8fixed in 6.8.8, 7.6.2
Mar 182021Privilege Context Switching Error in Elasticsearch
CVE-2020-7020Low3.1fixed in 6.8.13, 7.9.2
Mar 182021Exposure of Sensitive Information to an Unauthorized Actor
CVE-2021-22134Medium4.3fixed in 7.11.0
About Elasticsearch

The search and analytics engine.

Packages watched: org.elasticsearch:elasticsearch (Maven).

Elastic elsewhere on fru.dev: Acquisitions · Quarterly · Paydays · Releases · Repos · TechConf

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.