Elastic

Elasticsearch

91 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:11:00
  • Zuletzt bearbeitet 01.09.2026 14:58:27

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the ...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 19:10:58
  • Zuletzt bearbeitet 01.09.2026 15:03:00

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of ...

  • EPSS 0.26%
  • Veröffentlicht 13.08.2026 19:10:56
  • Zuletzt bearbeitet 01.09.2026 15:04:10

A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a dis...

  • EPSS 0.29%
  • Veröffentlicht 13.08.2026 19:10:53
  • Zuletzt bearbeitet 01.09.2026 15:04:40

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upp...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 19:10:51
  • Zuletzt bearbeitet 01.09.2026 15:22:55

A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to submit a request that causes a s...

  • EPSS 0.24%
  • Veröffentlicht 21.07.2026 23:10:49
  • Zuletzt bearbeitet 03.08.2026 15:58:28

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumpt...

  • EPSS 0.24%
  • Veröffentlicht 21.07.2026 22:26:43
  • Zuletzt bearbeitet 03.08.2026 16:07:28

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded ...

  • EPSS 0.24%
  • Veröffentlicht 21.07.2026 21:04:01
  • Zuletzt bearbeitet 07.08.2026 20:08:43

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised duri...

  • EPSS 0.24%
  • Veröffentlicht 21.07.2026 20:20:07
  • Zuletzt bearbeitet 07.08.2026 20:09:29

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available ...

  • EPSS 0.3%
  • Veröffentlicht 21.07.2026 20:17:02
  • Zuletzt bearbeitet 07.08.2026 20:10:36

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can sen...