CVE Tools

Logstash

45 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Logstash, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Logstash CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Logstash CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-041
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 45 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical37%
  • High2249%
  • Medium1840%
  • Low24%

Latest CVEs

The 15 most recently published vulnerabilities affecting Logstash.

  1. CVE-2026-33466Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write8.1
  2. CVE-2025-37730Logstash Improper Certificate Validation in TCP output6.5
  3. CVE-2022-46337Apache Derby: LDAP injection vulnerability in authenticator9.8
  4. CVE-2023-46672Logstash Insertion of Sensitive Information into Log File8.4
  5. CVE-2023-39410Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK7.5
  6. CVE-2022-4245Codehaus-plexus: xml external entity (xxe) injection4.3
  7. CVE-2022-4244Codehaus-plexus: directory traversal7.5
  8. CVE-2023-33201Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certif...5.3
  9. CVE-2023-34455snappy-java's unchecked chunk length leads to DoS7.5
  10. CVE-2023-34454snappy-java's Integer Overflow vulnerability in compress leads to DoS5.9
  11. CVE-2023-34453snappy-java's Integer Overflow vulnerability in shuffle leads to DoS5.9
  12. CVE-2023-2976Use of temporary directory for file creation in `FileBackedOutputStream` in Guava5.5
  13. CVE-2022-47318ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the prod...8.0
  14. CVE-2022-46648ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the prod...8.0
  15. CVE-2022-1471Remote Code execution in SnakeYAML8.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store