Elastic

Elasticsearch

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 06.10.2026 19:31:53
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorizat...

  • EPSS 0.3%
  • Veröffentlicht 06.10.2026 19:31:51
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an...

  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:31:50
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in ...

  • EPSS 0.4%
  • Veröffentlicht 06.10.2026 19:31:49
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its se...

  • EPSS 0.3%
  • Veröffentlicht 06.10.2026 19:31:47
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled ...

  • EPSS 0.3%
  • Veröffentlicht 06.10.2026 19:31:43
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template r...

  • EPSS 0.3%
  • Veröffentlicht 06.10.2026 19:31:40
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).

  • EPSS 0.34%
  • Veröffentlicht 06.10.2026 19:31:39
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular ...

  • EPSS 0.22%
  • Veröffentlicht 06.10.2026 19:31:37
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could...

  • EPSS 0.3%
  • Veröffentlicht 06.10.2026 19:31:34
  • Zuletzt bearbeitet 07.10.2026 13:42:52

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the qu...